A Zoom flaw let one meeting participant take over another's device, poisoned WordPress plugins quietly created hidden admin accounts, and Claude's output now carries an invisible watermark
Update Zoom: a flaw let someone in your meeting take over your device
Zoom has fixed a set of flaws in the drawing tools that let meeting participants annotate a shared screen. Chained together, they allowed a person who had joined a meeting to run code on another participant's machine — no click, no download, and nothing for the victim to notice. Zoom's own bulletin describes a missing bounds check in the annotator function that could let a meeting participant execute code remotely on another participant, rated high severity, and a second bulletin covers a related memory flaw in the same feature. The fixed versions are Zoom Workplace 7.1.5 or 7.0.6 and later on every platform, Zoom Rooms 7.1.0, and the VDI client at 7.0.11 or 6.6.16. Older versions are affected on Windows, macOS, iOS and Android alike.
The other half of the story is how it was found. Researchers reported building a working exploit in under a day using fewer than twenty prompts to publicly available AI models. There is no report of the flaw being used against anyone before the fix shipped.
Why it matters: this is the kind of flaw that needs no mistake from you — joining a meeting was enough — and video calls are one of the few pieces of software almost every business has open with strangers in the room. Open Zoom, check the version under its settings or profile menu, and let it update to 7.1.5 (or 7.0.6 on the older track) before your next outside meeting; if your computers are managed by someone else, ask them to confirm the rollout rather than assume it. The research half is worth registering too: the gap between a flaw existing and someone having a working attack for it is getting shorter, which makes "install the update this week" a meaningfully different habit from "install it eventually".
Poisoned WordPress plugins created hidden administrator accounts
A set of WordPress plugins used on hundreds of thousands of sites was turned against the people running them, without a single line of the plugin code being changed. Wordfence's advisory explains that attackers gained write access to the vendor's storage and poisoned the data feed behind a promotional banner the plugins display in the WordPress dashboard — so the malicious code arrived from outside, through a component that was working as designed. When a logged-in administrator loaded the dashboard, the injected script used that session to create a new administrator account, hidden from the user list, and in some cases installed a backdoor disguised as a plugin.
The affected products are BdThemes plugins, among them Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery and Ultimate Store Kit — add-ons for the Elementor page builder, with more than 350,000 installations between them. Reporting on the campaign says the attacks were detected on August 7, that the poisoned feed was serving clean data again by August 8, and that the plugins were pulled from the WordPress plugin directory while the vendor investigates. Accounts created before that point stay in place until someone removes them.
Why it matters: the vector is closed, so the question is not whether you are still being attacked but whether something was left behind. If your site runs Elementor with any of those add-ons, log into WordPress today and open Users → All Users: look for administrator accounts you do not recognise, then check the total user count against the number of accounts actually listed, because the attack hid its account from that list. Also look through Plugins for anything you did not install. If you find either, or you are not sure, treat it as a compromised site — change the passwords of every remaining administrator, and get whoever maintains the site to run a malware scan before you carry on. Sites that never had these plugins installed are unaffected.
Claude's text and files now carry an invisible mark
Anthropic has started embedding a machine-readable watermark in the text its Claude models produce, and signed provenance data in the image files they generate. The company's support page says the text watermark is imperceptible and travels with the text when it is copied and pasted elsewhere, while generated SVG, PNG and JPG files carry signed metadata using the open C2PA standard. It applies across the company's products — the Claude apps, its developer platform, its coding and work tools, and the versions hosted on the major cloud providers. Models released on or after August 2 include it from launch, and earlier ones are being updated. The change was prompted by European transparency rules but is being applied worldwide.
The limits are stated plainly by the company. A mark shows the text passed through Claude, not that Claude wrote it — people use these tools to edit and translate their own writing. And an absence of a mark proves nothing, since heavy editing or a change of file format can strip it.
Why it matters: if you or your staff use Claude to draft anything that goes to a client, a marketplace, a publisher or a school, assume that text can be identified as AI-processed after the fact, including once it has been pasted into a document or an email. That is not a reason to stop — it is a reason to know your own policy before someone else asks. Decide what you are comfortable saying about how your work is produced, and check whether anyone you supply has rules about AI-assisted material, because "we could not tell" is no longer the safe assumption on either side of that conversation. Detection tools for third parties are promised but not yet published.
Spotify will badge AI artist profiles and keep them out of recommendations
Spotify is adding a label for artist profiles that are generative AI creations rather than real performers. Its announcement says accounts can declare themselves as an AI Persona from August 11, that Spotify will also apply a "Likely AI Persona" badge using a mix of automated and human review, and that music from these accounts will be left out of personalised recommendations by default unless a listener chooses to follow them. The badges start appearing in mid-September, on mobile first, on profiles and in search and playlist track listings. Artists who are labelled are told, and can appeal.
Why it matters: for listeners this mostly means the recommendation feeds start behaving differently, with fully synthetic acts filtered out of them unless you opt in. For anyone who releases music — including businesses using it for podcasts, video or in-store audio — the practical point is the self-declaration window that opened today: labelling yourself is treated differently from being detected and badged, and the appeal process exists because automated detection will get some cases wrong. If you publish music that uses AI in any part of its production, look at how the platform defines the label before mid-September rather than after.
A fake Wi-Fi network on a Delta flight is being investigated
Someone on a Delta flight from Las Vegas to Atlanta set up a Wi-Fi network imitating the aircraft's own, and the crew shut the real network off for about half an hour after the pilots reported it. Delta says the safety of the flight was never in question and no aircraft systems were affected, and that it is investigating with federal law enforcement and aviation regulators. Who set it up, and why, is not established. The equipment needed is sold openly and is small enough to sit in a bag.
Why it matters: the trick works because a network name is not proof of anything — anyone can broadcast one that reads exactly like the real thing, on a plane, in a hotel lobby or in a café. If you connect to something that only imitates the genuine network, whoever runs it sits between you and everything you do. Two habits cover most of the risk: get the exact network name from the airline's or venue's own printed card or seatback material rather than picking the most plausible-looking one from the list, and never enter a password, card number or work login on a page that a public network pushed at you after you connected. Turn off automatic joining of open networks on your phone and laptop so the choice is always yours, and leave sensitive work for a mobile hotspot you control.