---
title: "#AxisOfEasy 318: Security Risks Loom Over Public Zoom Meeting Links"
type: "post"
post_id: "28566"
slug: "axisofeasy-318-security-risks-loom-over-public-zoom-meeting-links"
canonical: "https://axisofeasy.com/aoe/axisofeasy-318-security-risks-loom-over-public-zoom-meeting-links/"
markdown_url: "https://axisofeasy.com/aoe/axisofeasy-318-security-risks-loom-over-public-zoom-meeting-links.md"
json_url: "https://axisofeasy.com/aoe/axisofeasy-318-security-risks-loom-over-public-zoom-meeting-links.json"
txt_url: "https://axisofeasy.com/aoe/axisofeasy-318-security-risks-loom-over-public-zoom-meeting-links.txt"
published: "2023-10-06T22:00:52+00:00"
modified: "2023-10-06T15:46:36+00:00"
author: "Mark E. Jeftovic"
categories:
  - "#AxisOfEasy"
tags:
excerpt: "Security Risks Loom Over Public Zoom Meeting Links,  Renowned Authors Fight Back Against OpenAI's Unauthorized Content Use in LLM Training,  Canada Imposes Mandatory Registration for Podcast Platforms Under Government Authority... this and more in AofE  #318"
site_name: ""
publisher: ""
language: "en-US"
license: ""
generator: "easyPress AI Discoverability"
generator_version: "2.0.14"
---
*![](https://axisofeasy.com/wp-content/uploads/2020/02/weekly-briefing-axis-of-easy.jpg)*---

*Weekly Axis Of Easy #318*
==========================

---

***Last Week’s Quote was:*** *“A pessimist sees the difficulty in every opportunity; an optimist sees the opportunity in
every difficulty,” was by Winston Churchill. Our winner is Rich. Congrats!* ***This Week’s Quote: “****When a well-packaged web of lies has been sold gradually to the masses over generations, the truth will seem utterly preposterous and its speaker a raving lunatic.” By ???*
 ***THE RULES:*** *No searching up the answer, must be posted at the bottom of this post, in the comments section.*

***The Prize:*** *First person to post the correct answer gets their next domain or hosting renewal on us.*

 

 

---



***This is your easyDNS #AxisOfEasy Briefing for the week of October 1st, 2023 our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.*** 

 

 

 ***To Listen/watch this podcast edition with commentary and insigh from Joey Tweets, and Len the Legend click [here.](https://youtu.be/h1oAqbllUE8)*** 

***In this issue:***

- **Security Risks Loom Over Public Zoom Meeting Links**
- **Renowned Authors Fight Back Against OpenAI’s Unauthorized Content Use in LLM Training**
- **Canada Imposes Mandatory Registration for Podcast Platforms Under Government Authority**
- **Canada Faces Cyber Onslaught from Indian Hacker Group**
- **Critical Vulnerabilities Uncovered in WS\_FTP Server Software**
 
 ***Elsewhere online:***

- **Decoding the CRTC’s New Rules for Online News Services and Podcast Providers**
- **Reddit Tightens Ad Policy, Removes Opt-Out for Personalized Ads**
- **Emergence of BunnyLoader: A New Malware-as-a-Service Threat in the Cybercrime Underground**
- **KillNet Strikes: DDoS Attack Hits UK Royal Family Website**
- **AWS Employing MadPot Decoy System for Disrupting APTs and Botnets**
 
 

 

[**Security Risks Loom Over Public Zoom Meeting Links** ](https://krebsonsecurity.com/2023/10/dont-let-zombie-zoom-links-drag-you-down/)
A recent investigation has uncovered potential security risks associated with Zoom links. Numerous organizations, including some Fortune 500 companies, have inadvertently exposed web links that could allow any individual to initiate a Zoom video conference meeting posing as an employee.

The crux of the issue lies with the Zoom Personal Meeting ID (PMI), a permanent identification number linked to each Zoom account. This PMI is part of every new meeting URL created by that account. While this feature offers convenience, it also poses a significant security risk. If a PMI link falls into the wrong hands, it can be used to gain access to any ongoing meeting associated with that PMI unless additional security measures such as meeting locks or Zoom’s Waiting Room feature are activated. The situation is further exacerbated if these Zoom links are indexed by search engines like Google, a scenario that is reportedly true for thousands of organizations.

Charan Akiri, a security engineer at Reddit, has drawn attention to the potential misuse of PMI links. He cautions that these readily accessible links can be manipulated by attackers for impersonation purposes. As Akiri puts it, “These vulnerabilities allow attackers to masquerade as companies and initiate meetings without users’ knowledge. They can interact with other employees or customers under the guise of the company, potentially gaining unauthorized access to sensitive information.”

*Read: https://krebsonsecurity.com/2023/10/dont-let-zombie-zoom-links-drag-you-down/*


[**Renowned Authors Fight Back Against OpenAI’s Unauthorized Content Use in LLM Training**](https://www.mondaq.com/unitedstates/copyright/1371906/famous-authors-clap-back-at-openais-attempt-to-dismiss-claims-regarding-unauthorized-use-of-content-for-training-llm-models)

Generative AI’s rise has triggered copyright suits across the country, with OpenAI as a major target. Plaintiffs, including Sarah Silverman, Paul Tremblay, George R.R. Martin, and John Grisham, allege unauthorized use of their content by OpenAI to train its AI tool, violating the U.S. Copyright Act.

OpenAI chose not to seek dismissal of the direct copyright infringement claims brought by the plaintiffs, Sarah Silverman and Paul Tremblay. Instead, OpenAI focused on vicarious liability and the plaintiffs’ failure to demonstrate substantial similarity between ChatGPT’s outputs and their works under the DMCA.

Regarding the DMCA allegations, the Plaintiffs asserted that “OpenAI intentionally removed CMI from” their works that were protected and that, among other things, their creations included CMI. However, OpenAI will respond before the court’s decision. This case is significant as it will determine if LLMs can use others’ creative content for training without compensating the rights holders.

*Read:*
*https://www.mondaq.com/unitedstates/copyright/1371906/famous-authors-clap-back-at-openais-attempt-to-dismiss-claims-regarding-unauthorized-use-of-content-for-training-llm-models*


[**Canada Imposes Mandatory Registration for Podcast Platforms Under Government Authority**](https://reclaimthenet.org/canada-forces-even-podcast-platforms-to-register-with-the-government)

Recently, the Canadian Radio-television and Telecommunications Commission (CRTC) unveiled stringent regulations mandating the registration of all digital platforms that transmit audio or visual content and achieve a specific earnings threshold. This registration requirement must be fulfilled with the government agency by the end of November.

The regulatory requirement will apply to both traditional radio stations and online live-streaming podcast services, leaving no exceptions. However, platforms that generate less than $10 million in annual broadcasting revenues in Canada, along with video games and audiobook services, will be exempt from this rule.

This regulation signifies increased government control over the digital landscape, raising concerns about threats to net neutrality and freedom of speech. It foreshadows a potential conflict between individual freedom, free speech, and the unexplored realm of digital censorship.

*Read: https://reclaimthenet.org/canada-forces-even-podcast-platforms-to-register-with-the-government*


[**Canada Faces Cyber Onslaught from Indian Hacker Group**](https://www.cbc.ca/news/politics/cyberattacks-parliament-india-1.6981399)

Canada’s federal government has been grappling with a series of cyberattacks. A hacker group from India, known as the Indian Cyber Force, has claimed responsibility. Despite the disruption, Canada’s signals intelligence agency maintains that these attacks have not compromised private information.

The Canadian Armed Forces’ website was temporarily inaccessible to mobile users due to a distributed denial-of-service (DDoS) attack. The site was restored within a few hours. The House of Commons website also experienced slow or incomplete loading due to an ongoing DDoS attack. Elections Canada was hit by a denial-of-service attack that lasted about an hour.

The Indian Cyber Force has not only claimed responsibility for the military incident but also appears to have infiltrated several websites owned by small Canadian businesses. The group posted messages criticizing Canada for allegedly providing refuge to terrorists and insulting Sikh separatists. They also criticized Prime Minister Justin Trudeau for making allegations without proof.

The U.S., a close ally of Canada, has urged India to cooperate with the Canadian investigation into these cyberattacks. However, it remains to be seen how this international cyber incident will unfold and what measures will be taken to prevent such attacks in the future.

*Read: https://www.cbc.ca/news/politics/cyberattacks-parliament-india-1.6981399*


[**Critical Vulnerabilities Uncovered in WS\_FTP Server Software**](https://www.darkreading.com/cloud/moveit-progress-critical-bug-ws_ftp-software)

Progress Software, a company that offers file-transfer solutions to an estimated 40 million users, has discovered critical vulnerabilities in its WS\_FTP Server software. It’s crucial to clarify that these vulnerabilities are specific to the server software and do not impact the FTP client. The most dangerous of these vulnerabilities enables remote code execution (RCE) without user interaction or authentication. This discovery follows a previously disclosed zero-day vulnerability in Progress’s MOVEit file transfer technology.

The most critical vulnerability, CVE-2023-40044, is present in WS\_FTP Server versions prior to 8.7.4 and 8.8.2. This vulnerability is a .NET serialization issue that could enable denial-of-service attacks, information leaks, and RCE. Another significant vulnerability is a directory traversal issue, CVE-2023-42657, present in WS\_FTP Server versions before 8.7.4 and 8.8.2, which could permit attackers to manipulate files outside their authorized WS\_FTP folder path.

Additionally, there are two high-severity cross-site scripting (XSS) vulnerabilities (CVE-2023-40045 and CVE-2023-40047) that could enable the execution of malicious JavaScript. Medium security flaws include a cross-site request forgery (CSRF) issue (CVE-2023-40048) and an information disclosure problem (CVE-2023-40049). To identify instances of WS\_FTP Server, organizations are advised to utilize software inventory tools and network monitoring tools, which can be particularly effective due to the open incoming ports typically associated with the software.

*Read: https://www.darkreading.com/cloud/moveit-progress-critical-bug-ws\_ftp-software*

***Elsewhere online:***

**Decoding the CRTC’s New Rules for Online News Services and Podcast Providers**
*Read: https://www.michaelgeist.ca/2023/10/crtcregistrationregs/*


**Reddit Tightens Ad Policy, Removes Opt-Out for Personalized Ads**
*Read: https://www.mediapost.com/publications/article/389707/redditors-no-longer-able-to-opt-out-of-personalize.html*


**Emergence of BunnyLoader: A New Malware-as-a-Service Threat in the Cybercrime Underground**
*Read: https://thehackernews.com/2023/10/bunnyloader-new-malware-as-service.html*


**KillNet Strikes: DDoS Attack Hits UK Royal Family Website**
*Read: https://www.hackread.com/uk-royal-family-website-ddos-attack-killnet/*


**AWS Employing MadPot Decoy System for Disrupting APTs and Botnets**
*Read: https://www.securityweek.com/aws-using-madpot-decoy-system-to-disrupt-apts-botnets/*

**Previously on #AxisOfEasy**

 

 

 

 

 

 

 

 

 

**If you missed the previous issues, they can be read online here:**

- [September 24th, 2023: Xenomorph Malware Spreads To Spanish And American Banks In Latest Campaign](https://axisofeasy.com/317)
- [September 18th, 2023: Wordfence Threat Intelligence Team Issues Fix For Two PHP Object Injection Vulnerabilities](https://axisofeasy.com/316)
- [September 11th, 2023: Armed By AI Technology, Hackers Cause A 464% Rise In Email-Based Phishing During The First Half Of 2023](https://axisofeasy.com/315)
- [September 4th, 2023: Key Cracking Concerns Emerge From LastPass Breach](https://axisofeasy.com/314)
- [August 28th, 2023: IoT Devices Under Attack: KmsdBot Malware Evolves With Enhanced Capabilities](https://axisofeasy.com/313)
