Zombie Card Attack Revives Expired Visa Cards for Contactless NFC Payments
Researchers from the University of Massachusetts Amherst have demonstrated an attack called Zombie Card that allows contactless payments using certain expired Visa cards over NFC. The technique does not require breaking cryptography or cloning the card; it relies solely on inconsistencies in how terminals and banks verify the card’s expiration date.
The team presented their findings in a paper at USENIX Security. For the experiment, researchers placed two Android smartphones between an expired card and a payment terminal. One device emulated the card while the other emulated the terminal, relaying data in real time. During the transaction, the system intercepted the EMV field containing the expiration date and replaced the expired value with a future date.
The terminal accepted the card after performing its local check. The cryptographic data for the transaction remained valid because the modifiable expiration field in Visa EMV Kernel 3 is not always cryptographically bound to the protected elements. However, the attack has limitations: the card’s keys must still be active, and the linked account and card number must remain operational.
Bank behavior varied during testing. One issuer approved payments of varying amounts at different merchants, while another issuer consistently rejected the transactions and directed customers to obtain new cards. Similar substitution attempts failed on Mastercard, American Express, and Discover because their implementations either cross-checked multiple representations of the expiration date or protected the relevant data cryptographically.
The attack is more complex than conventional skimming because it requires both a physical expired card and an NFC relay positioned near the payment terminal.
Related articles
CISA Adds Two Remotely Exploitable TrueConf Server Vulnerabilities to KEV Catalog
The US Cybersecurity and Infrastructure Security Agency has added two critical vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog. CVE-2026-72529 allows unauthenticated remote attackers to execute arbitrary scripts due to missing authentication in a critical function. CVE-2026-72530 is a code injection flaw that enables attackers to run arbitrary code on the underlying host system by escaping the sandboxed environment. Both issues can be exploited over TCP port 4307 without requiring authentication. Kaspersky assigned CVSS v3.1 base scores of 9.8 and 9.0 respectively, rating both as Critical. US federal agencies must apply mitigations for the first vulnerability by August 23 and for the second by September 3.
Critical Unauthenticated File Upload Flaw in Elementor Pro Allows Remote Code Execution on WordPress Sites
A critical vulnerability tracked as CVE-2026-32475 has been discovered in the Elementor Pro plugin for WordPress, enabling unauthenticated attackers to upload and execute arbitrary PHP code. The flaw resides in the file upload module where validation and saving processes handle empty filenames inconsistently across multipart requests. Attackers can bypass checks by sending one part with an empty filename and another containing a PHP backdoor, which gets stored in the publicly accessible wp-content/uploads/elementor/forms/ directory. Exploitation requires a published Elementor Pro form with the multiple-file upload option enabled, a setting that is disabled by default. The free version of Elementor remains unaffected, while the issue was resolved in Elementor Pro 4.2.2. Administrators are urged to update immediately and scan upload directories for unauthorized PHP files, as no active exploitation has been observed yet but public disclosure increases the risk.
Claude Discovers Vulnerabilities Across 16 SAML Projects in One Month, Exposing Maintenance Gaps
Security researcher Eric Chiang used Anthropic's Claude Opus model to identify vulnerabilities in 16 SAML implementations over roughly one month of evening work. The effort uncovered four full authentication bypasses in projects including Authentik, lightsaml, OneUptime, and saml-client, plus twelve additional signature bypass issues affecting secondary protocol messages. A notable finding was CVE-2026-57580 in Authentik, independently reported by eight researchers, which allowed XML comment injection in the NameID field to hijack accounts under specific configuration settings. Chiang built a two-phase agent pipeline that first searched for behavioral anomalies in libraries and then combined them into working exploits, without needing to train the model on prior SAML vulnerabilities. Many maintainers either ignored reports or struggled to distinguish real issues from AI-generated noise, with one project requiring three iterations of fixes before the patches held. The researcher concluded that while discovering SAML flaws has become inexpensive, patching them remains costly and under-resourced, reinforcing his long-standing recommendation to avoid custom SAML code in favor of established libraries or OpenID Connect.
Mind Games: 30 Years of Hacking and Securing Game Consoles
The article traces the evolution of security mechanisms in home game consoles from the unprotected Atari 2600 in 1977 through hardware locks, optical media protections, and cryptographic boot chains up to the seventh generation. Early systems like the NES relied on the 10NES/CIC chip for mutual authentication using identical Sharp SM590 microcontrollers, which was quickly defeated by Tengen's Rabbit clone and physical pin-clipping attacks. PlayStation introduced SCEx regional signals on discs, leading to widespread modchip installations and swap tricks that bypassed all code verification. Microsoft’s original Xbox implemented a full cryptographic chain of trust starting from the MCPX southbridge, yet it fell to HyperTransport bus sniffing by bunnie Huang and buffer overflows in titles such as MechAssault. Nintendo Wii’s Twilight Hack exploited a stack overflow via an excessively long horse name in The Legend of Zelda: Twilight Princess, enabling unsigned code execution. The piece highlights recurring lessons about the limits of security-through-obscurity and the necessity of protecting both boot chains and runtime memory handling.