Zombie Card Attack Revives Expired Visa Cards for Contactless NFC Payments
Researchers from the University of Massachusetts Amherst have demonstrated an attack called Zombie Card that allows contactless payments using certain expired Visa cards over NFC. The technique does not require breaking cryptography or cloning the card; it relies solely on inconsistencies in how terminals and banks verify the card’s expiration date.
The team presented their findings in a paper at USENIX Security. For the experiment, researchers placed two Android smartphones between an expired card and a payment terminal. One device emulated the card while the other emulated the terminal, relaying data in real time. During the transaction, the system intercepted the EMV field containing the expiration date and replaced the expired value with a future date.
The terminal accepted the card after performing its local check. The cryptographic data for the transaction remained valid because the modifiable expiration field in Visa EMV Kernel 3 is not always cryptographically bound to the protected elements. However, the attack has limitations: the card’s keys must still be active, and the linked account and card number must remain operational.
Bank behavior varied during testing. One issuer approved payments of varying amounts at different merchants, while another issuer consistently rejected the transactions and directed customers to obtain new cards. Similar substitution attempts failed on Mastercard, American Express, and Discover because their implementations either cross-checked multiple representations of the expiration date or protected the relevant data cryptographically.
The attack is more complex than conventional skimming because it requires both a physical expired card and an NFC relay positioned near the payment terminal.
Related articles
Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ
SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.
WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution
WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.
Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory
Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.
EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners
EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.