LIVE · cybersecurity feed
Live wire
security

Zombie Card: An expired Visa credit card can be used for purchases

Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

zeroday.news ·

Researchers have identified a vulnerability, dubbed "Zombie Card," that could allow expired Visa contactless credit cards to be used for in-store purchases by manipulating the expiration date presented to payment terminals. The flaw was discovered by University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza.

The researchers found that in certain configurations, specifically within the Visa Kernel 3 contactless transaction flow, the application expiration date displayed to the terminal was not sufficiently protected or linked to the card's internal data. This allowed them to modify the expiration date seen by the terminal to a future date, effectively "reviving" expired Visa cards for real transactions.

Their testing involved contactless cards from Visa, Mastercard, Discover, and American Express, issued by five major U.S. banks, and used across various terminals and merchants. While the vulnerability was specific to Visa, the results were not uniform even among Visa cards; some transactions were declined or prompted for a replacement card, while others were approved. In contrast, tested Mastercard, American Express, and Discover configurations consistently rejected altered expiration data due to robust consistency checks or authenticated data coverage.

The most plausible scenario for exploitation involves an attacker obtaining an expired or replaced card that the owner might consider harmless, such as one found in household waste, a lost wallet, or an unsecured disposal stream. If the underlying account remains active and the card issuer's systems do not thoroughly validate the card's lifecycle status, an attacker could potentially make contactless purchases using a relay setup. A less likely scenario involves a proximity relay attack against a card still in the owner's possession, which would require sustained NFC proximity and a live relay during the transaction.

For cardholders, the recommended precaution is to physically destroy expired and replacement cards. This includes cutting through the chip multiple times, making additional cuts to disrupt the contactless antenna, and damaging the magnetic stripe before disposal. Additionally, reporting a lost expired card is advised rather than assuming it is inert. However, the primary responsibility for addressing this vulnerability lies with payment networks, terminal implementers, and card issuers to ensure that expiration data is integrity-protected and that authorization systems correctly reject retired card credentials.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.

phishing

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Microsoft rolls out Classic Outlook theme for New Outlook users

Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]

ai

OpenAI Adds Controls That Should've Been There Already

The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.

security

North Korean Hackers Tied to Rust Supply Chain Attack

Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks