Security News

Zoom Beefs Up End-to-End Encryption to Thwart ‘Zoombombers’
2020-05-07 16:43

The 25-person, New York-based company will provide more robust encryption for Zoom calls on paid subscriptions by implementing an end-to-end architecture. "Logged-in users will generate public cryptographic identities that are stored in a repository on Zoom's network and can be used to establish trust relationships between meeting attendees," Zoom CEO Eric Yuan explained in a Thursday blog post.

Zoom Acquires Keybase to Bring End-to-End Encryption to Video Platform
2020-05-07 13:45

Popular communications platform provider Zoom Video announced on Thursday that it has acquired secure messaging and file-sharing service Keybase for an undisclosed sum. The move is the latest by the company as it attempts to bolster the security of its offerings and build in end-to-end encryption that can scale to the company's massive user base.

Zoom 5.0: How to better secure meetings with the latest features
2020-05-06 18:00

With the new 5.0 version of Zoom, the app has added features to help you protect your virtual meetings from Zoombombing and other unwanted intrusion.

Zoom: A cheat sheet about the video conferencing solution
2020-04-30 16:38

Is Zoom still a video conferencing app worth using? If so, who should use it when so much personal and business security could be at risk? Learn more by reading this Zoom basics guide. March 30: Another investigation finds that Zoom is not using end-to-end encryption, Zoom bombs are first reported, and multiple flaws in both the windows and macOS versions of Zoom are reported.

Securing Internet Videoconferencing Apps: Zoom and Others
2020-04-30 15:24

Zoom does offer end-to-end encryption if 1) everyone is using a Zoom app, and not logging in to the meeting using a webpage, and 2) the meeting is not being recorded in the cloud. The Zoom transport protocol adds Zoom's own encryption scheme to RTP in an unusual way.

Zoom 5.0: How to better secure meetings with the latest features
2020-04-29 13:38

With the new 5.0 version of Zoom, the app has added features to help you protect your virtual meetings from Zoombombing and other unwanted intrusion. As described in a blog post published last week, Zoom 5.0 brings with it 256-bit encryption to better secure meeting data, meeting passwords that are turned on by default, passwords required to access recorded meetings stored in the cloud, and other security features.

Troves of Zoom Credentials Shared on Hacker Forums
2020-04-28 10:00

Learn more about what Maor's investigations into underground forums have revealed about how credentials are being uncovered, shared and leveraged to attack remote workers, in this week's Threatpost podcast. Now, a few weeks back, you had found that there were more than 2,000 compromised Zoom credentials that were missing being shared on underground forums.

Warning! Fake Zoom “HR meeting” emails phish for your password
2020-04-28 08:30

Example CEO and Management Board Meeting for all staffs on Zoom Meeting This is a reminder that your zoom meeting appointment with H.R and Audit Head will start in few minutes. Your presence is crucial to this meeting and equally required to commence this Q1 perfomance review meeting Join this Live Meeting Meeting Purpose: Contract Suspension / Termination Trial.

Obsidian Security lets security teams monitor Zoom usage
2020-04-27 14:23

Obsidian Security announced protection for Zoom, enabling organizations to safely embrace the leading video communications service as a business-critical application. "Board meetings, medical appointments, and critical customer calls are all occurring over Zoom. Security teams are grappling with how to prevent account misuse and ensure that only the right people are in these meetings," said Glenn Chisholm, CEO of Obsidian.

Week in review: Web shell malware, client-side web security, phishers exploit Zoom and WebEx
2020-04-26 08:55

Web shell malware continues to evade many security toolsCyber attackers are increasingly leveraging web shell malware to get persistent access to compromised networks, the US National Security Agency and the Australian Signals Directorate warn. Phishers exploit Zoom, Webex brands to target businessesProofpoint researchers have spotted and documented email phishing campaigns targeting US companies in a variety of industries with emails impersonating Zoom and Cisco.