RCE vulnerabilities, joins rooms without consent, tries very hard to persist beyond uninstalls. And their security attitude mirrors SCdF's: Your company forces you to use us, fuck you.
let me expand (copy pasta from my comment on sibling post[0]):
this isn't the first time zoom got caught red-handed[1]. Last year they were called out for installing a local web server in order to disable security controls to get around the deprecated NPAPI[2] ... this is _literally_ what malware does. Seriously fuck zoom!