The Phone Was Still Ringing. WeChat Had Already Lost the Account.

Researchers built a wormable WeChat account takeover that required no answer or tap. Tencent says the path is fixed and there is no evidence attackers used it.

Researchers built a wormable WeChat account takeover that required no answer or tap. Tencent says the path is fixed and there is no evidence attackers used it.

Zoom has patched a set of memory-safety vulnerabilities that researchers combined into a zero-click remote-code-execution attack through the live-meeting annotation protocol. A malicious participant could target a presenter, while a malicious presenter could reach participants across Windows, macOS, iOS and…