-
Suspicious Process Execution by Zoom
Sep 19, 2026 · Domain: Endpoint OS: Linux OS: macOS Use Case: Threat Detection Use Case: Vulnerability Tactic: Execution Data Source: Elastic Defend Rule Type: Event Correlation (EQL) Resources: Investigation Guide Platform: Linux Platform: macOS Domain: SaaS Data Source: Zoom Vuln: CVE-2026-53413 ·Identifies suspicious process execution associated with the Zoom desktop client on macOS and Linux. The rule detects shells, script interpreters, downloaders, and network utilities spawned by Zoom on either platform. On Linux, it also detects Zoom replacing its own process image with an executable outside the Zoom installation directory. These behaviors may indicate successful exploitation of a Zoom client vulnerability, including CVE-2026-53413.
Read More