YoVDO

Zoom 0-Day - How Not to Handle a Vulnerability Report

Offered By: 0xdade via YouTube

Tags

ShmooCon Courses Communication Skills Courses Cybersecurity Courses Vulnerability Assessment Courses Software Supply Chain Security Courses

Course Description

Overview

Explore a detailed account of the 2019 Zoom 0-Day vulnerability disclosure in this conference talk from Shmoocon 2020. Delve into the discovery of a critical security flaw allowing malicious actors to activate Mac users' cameras without consent, and the hidden daemon that persisted after uninstallation. Follow the speaker's journey through the vulnerability reporting process, the decision to go public, and the escalating consequences that ultimately required intervention from Apple's security team. Gain insights into the complexities of responsible disclosure, corporate responses to security threats, and the potential ramifications of software vulnerabilities in widely-used applications.

Syllabus

Intro
Who is Jonathan
Why Zoom
Disclosure
Going Public
Zooms Response
Questions


Taught by

0xdade

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network