<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Zoom Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Zoom.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery</title><link>https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html</link><guid isPermaLink="false">cst-3180</guid><description>North Korean threat actors known as BlueNoroff are running phishing campaigns that impersonate Zoom and Microsoft Teams to deliver malware, leveraging typosquatted domains and compromised industry contacts. The group profiles cryptocurrency wallets during the social engineering process before distributing malicious payloads to targets.</description><pubDate>Fri, 24 Jul 2026 15:12:35 GMT</pubDate></item><item><title>MIT to Become Hotbed of AI Video Surveillance</title><link>https://schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html</link><guid isPermaLink="false">cst-2913</guid><description>MIT is installing over 500 AI-equipped surveillance cameras across campus buildings, residence halls, and outdoor areas between November 2025 and September 2026, with a budget exceeding $3 million. The cameras use deep learning to perform real-time facial recognition, object classification, and behavioral detection including motion, loitering, and crowd identification. Collected data is retained for up to 30 days unless an exception applies.</description><pubDate>Tue, 21 Jul 2026 11:07:13 GMT</pubDate></item><item><title>The Zoom hack that says, ‘Don’t record me’</title><link>https://techcrunch.com/2026/07/17/the-zoom-hack-that-says-dont-record-me</link><guid isPermaLink="false">cst-2788</guid><description>A commentary on the proliferation of recording and transcription features in video conferencing platforms like Zoom, questioning whether ubiquitous automated transcription and summarization serves practical value or creates information overload.</description><pubDate>Fri, 17 Jul 2026 21:20:47 GMT</pubDate></item><item><title>The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26</title><link>https://tenable.com/blog/black-hat-2026-swarm-event-build-AI-security-agents</link><guid isPermaLink="false">cst-2687</guid><description>Tenable is hosting Swarm, a collaborative build event at Black Hat 2026 where security practitioners will develop open-source AI agents and tools together. The event aims to address isolated development of agentic AI in security teams by fostering community collaboration on agents, skills, and model context protocol servers to improve collective cyber defenses.</description><pubDate>Thu, 16 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Splunk, Zoom Patch Critical Vulnerabilities</title><link>https://securityweek.com/splunk-zoom-patch-critical-vulnerabilities</link><guid isPermaLink="false">cst-2681</guid><description>Splunk and Zoom released patches for critical vulnerabilities that could enable attackers to obtain credentials, access data, take over user accounts, and elevate privileges.</description><pubDate>Thu, 16 Jul 2026 10:54:34 GMT</pubDate></item><item><title>Russian hackers trojanize WebEx, Zoom apps to push Starland malware</title><link>https://bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware</link><guid isPermaLink="false">cst-2650</guid><description>A Russian financially motivated threat actor identified as UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deliver Starland RAT, a new backdoor designed to steal credentials and cryptocurrency.</description><pubDate>Thu, 16 Jul 2026 10:19:34 GMT</pubDate></item><item><title>UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign</title><link>https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign</link><guid isPermaLink="false">cst-2666</guid><description>Cisco Talos identified UAT-11795, a Russian-speaking financially motivated threat actor conducting campaigns since at least June 2025 against victims in the U.S. and Europe. The group deploys Starland RAT, a Python-based remote access tool, alongside WLDR, a sophisticated PowerShell-based command-and-control implant featuring encrypted beaconing and task queuing capabilities. The actor distributes trojanized installers of legitimate software such as MobaXterm, WebEx, Zoom, and DBeaver to establish persistence and steal credentials and cryptocurrency assets.</description><pubDate>Thu, 16 Jul 2026 10:00:01 GMT</pubDate></item><item><title>Zoom warns of critical account takeover vulnerability</title><link>https://bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability</link><guid isPermaLink="false">cst-2633</guid><description>Zoom disclosed a critical vulnerability affecting its Windows desktop client and SDK that allows unauthenticated attackers to take over user accounts. The flaw poses a direct risk to Zoom meeting participants and administrators who have not yet patched their systems.</description><pubDate>Wed, 15 Jul 2026 20:16:02 GMT</pubDate></item><item><title>Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms</title><link>https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms</link><guid isPermaLink="false">cst-309</guid><description>UNC3753, a financially motivated threat group, conducted a data theft extortion campaign from January through May 2026 targeting US law firms and professional services organizations. The group used voice phishing and social engineering to trick employees into downloading remote access tools, then either searched systems directly or manipulated victims into stealing sensitive data like legal agreements and financial records for extortion. In some cases, actors physically entered corporate offices posing as IT technicians to extract data via USB media.</description><pubDate>Fri, 05 Jun 2026 14:00:00 GMT</pubDate></item><item><title>Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict</title><link>https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict</link><guid isPermaLink="false">cst-600</guid><description>Nimbus Manticore, an Iranian IRGC-affiliated threat actor, resurfaced during escalated US-Iran military tensions in early 2026 with enhanced capabilities including a new backdoor called MiniFast and novel delivery techniques. The group conducted phishing campaigns targeting aviation and software sector employees across the United States, Europe, and the Middle East, employing methods such as SEO poisoning, AppDomain hijacking, and abuse of legitimate Zoom installers. The malware development appeared to incorporate AI-assisted practices, enabling rapid tool adaptation and sustained operational activity.</description><pubDate>Fri, 22 May 2026 15:09:29 GMT</pubDate></item><item><title>The Internet Is Falling Down, Falling Down, Falling Down (cPanel &amp; WHM Authentication Bypass CVE-2026-41940)</title><link>https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940</link><guid isPermaLink="false">cst-560</guid><description>cPanel &amp; WHM, which manages over 70 million domains, contains an authentication bypass vulnerability (CVE-2026-41940) affecting all currently supported versions. The flaw in session loading and saving mechanisms has been exploited in the wild as a zero-day, and cPanel has released patches across multiple version tracks (110.0.x through 136.0.x) to address the issue.</description><pubDate>Wed, 29 Apr 2026 17:19:19 GMT</pubDate></item></channel></rss>