Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

A recent report highlighted several security incidents and developments, including a "Zombie Card" attack, a distributed denial-of-service (DDoS) attack against Threema, and the emergence of the Evooo1Bot Linux botnet. Additionally, T-Mobile reportedly severed a cable in an attempt to thwart attackers, while GitHub denied that artificial intelligence was responsible for a specific bug. Crypto4A also achieved top-tier NIST certification, marking a significant development in hardware security.
The "Zombie Card" attack refers to a type of financial fraud where previously canceled or expired credit card numbers are reactivated or exploited to make unauthorized purchases. This often involves exploiting vulnerabilities in payment processing systems or the way card issuers handle the lifecycle of card numbers. Attackers might leverage stolen card data and test various permutations or timing windows to bypass security controls, sometimes succeeding due to delays in system updates or inconsistent enforcement of card status across different payment gateways.
The DDoS attack against Threema, a secure messaging service, indicates an attempt to disrupt its availability by overwhelming its servers with a flood of malicious traffic. Such attacks typically involve a botnet, a network of compromised computers, sending a high volume of requests or data packets to the target, making it inaccessible to legitimate users. DDoS attacks can range in sophistication, from simple volumetric attacks to more complex application-layer attacks targeting specific services.
The Evooo1Bot Linux botnet represents a new threat targeting Linux-based systems. Botnets like Evooo1Bot typically compromise devices through vulnerabilities in unpatched software, weak credentials, or malicious downloads. Once a system is infected, it becomes part of the botnet, controlled remotely by attackers to launch further attacks, such as DDoS, cryptocurrency mining, or spreading malware. Securing Linux systems requires regular patching, strong password policies, and network segmentation.
T-Mobile's reported action of cutting a cable to stop attackers suggests a drastic measure taken in response to an active intrusion or data exfiltration attempt. This kind of physical intervention is typically reserved for severe incidents where logical controls have failed or are insufficient to contain a breach. While effective in immediately severing attacker access, it can also lead to service disruption for legitimate users and is usually a last resort.
GitHub's denial that artificial intelligence caused a specific bug addresses concerns about the role of AI in software development and potential new classes of vulnerabilities. As AI tools become more integrated into coding and testing workflows, questions arise about their potential to introduce novel errors or security flaws. This denial suggests an ongoing dialogue within the industry about the reliability and security implications of AI-assisted development.
Finally, Crypto4A's achievement of top-tier NIST certification for its hardware security module (HSM) is a significant milestone. NIST (National Institute of Standards and Technology) certifications, particularly FIPS 140-2 Level 3 or 4, are crucial for cryptographic modules used in government and high-security environments. This certification indicates that Crypto4A's HSM meets stringent security requirements for cryptographic key management, data protection, and tamper resistance, providing a high level of assurance for sensitive operations.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.