UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

Researchers at the University of Massachusetts Amherst have demonstrated a method to make purchases with expired Visa contactless credit cards, including at live retail and grocery merchants. The attack, presented at USENIX Security 2026, exploits a structural weakness in Visa's implementation of the EMV contactless payment protocol, specifically within its Kernel 3 software.
The vulnerability stems from an unsigned expiry field in Visa's EMV kernel. During a contactless transaction, the expiration date is presented twice: once in a field read by the payment terminal (tag 5F24, the Application Expiration Date) and once in a field read by the issuing bank (tag 57, Track 2 Equivalent Data). In Visa's Kernel 3, these two representations are not cryptographically linked.
The researchers developed a relay attack that intercepts the NFC communication between the card and the terminal. Using two NFC-capable Android phones running custom software, one emulating a card and the other a terminal, they were able to modify the expiry date seen by the payment terminal to a future date. Crucially, the data sent to the bank remained unchanged, preserving the card's valid digital signature because the expiry date is not covered by it.
This manipulation allows the bank to receive a transaction that appears legitimate and passes its normal security checks, despite the physical card being expired. The relay added approximately 20 milliseconds per communication round trip, with date modification adding another 30 milliseconds, keeping the total transaction time within Visa's 500-millisecond command limit. The test hardware did not utilize EMV's optional Relay Resistance Protocol, which could have detected the added latency.
Other major payment networks, including Mastercard, American Express, and Discover, were not susceptible to this specific attack. Mastercard's terminals check for consistency between the two expiry representations, treating a mismatch as an error. American Express binds the expiration date into the data covered by offline authentication, causing a hash mismatch if modified. Discover's kernel incorporates modified transaction objects into its verified transaction hash, leading to transaction failure. Visa's Kernel 3 lacks these protective measures.
The success of the attack also varied depending on the issuing bank. Researchers tested three banks with expired and replaced physical Visa cards. One bank (Bank A) accepted modified transactions at various amounts, including $1.00, $100.00, and $500.00 in lab settings, and completed real purchases of $2.79 and $3.19 at retail and grocery merchants. Bank A also alarmingly accepted simultaneous transactions from both an expired original card and its replacement against the same account. Another bank (Bank B) detected the modification but still accepted some transactions. A third bank, tested on Discover's kernel, declined the edited transactions but also exhibited the simultaneous-card problem without any modification.
Further findings revealed that the researchers could change the Consumer Device Cardholder Verification Method (CDCVM) flag at five US banks, with transactions succeeding at most of them. This flag, which controls how the terminal verifies the cardholder, can be altered because payment data can be modified in transit.
Another issue with Kernel 3 is its practice of sending a Terminal Verification Results (TVR) value filled with zeros to the issuer. This prevents the bank from knowing whether the terminal checked the card's expiry date or if that check failed, forcing the bank to approve transactions without full visibility into terminal-side validation.
The researchers concluded that the primary factors determining attack success are the EMV kernel in use and whether expiry data fields are cryptographically bound, issuer-side lifecycle enforcement regarding account and card instrument validation, and whether terminal-side validation results are visible to the issuer via TVR. Transaction amount, merchant category, and POS terminal brand did not independently influence the outcome.
The findings were disclosed to Visa in May 2025.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed