Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

Researchers have identified a vulnerability, dubbed "Zombie Card," that could allow expired Visa contactless credit cards to be used for in-store purchases by manipulating the expiration date presented to payment terminals. The flaw was discovered by University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza.
The researchers found that in certain configurations, specifically within the Visa Kernel 3 contactless transaction flow, the application expiration date displayed to the terminal was not sufficiently protected or linked to the card's internal data. This allowed them to modify the expiration date seen by the terminal to a future date, effectively "reviving" expired Visa cards for real transactions.
Their testing involved contactless cards from Visa, Mastercard, Discover, and American Express, issued by five major U.S. banks, and used across various terminals and merchants. While the vulnerability was specific to Visa, the results were not uniform even among Visa cards; some transactions were declined or prompted for a replacement card, while others were approved. In contrast, tested Mastercard, American Express, and Discover configurations consistently rejected altered expiration data due to robust consistency checks or authenticated data coverage.
The most plausible scenario for exploitation involves an attacker obtaining an expired or replaced card that the owner might consider harmless, such as one found in household waste, a lost wallet, or an unsecured disposal stream. If the underlying account remains active and the card issuer's systems do not thoroughly validate the card's lifecycle status, an attacker could potentially make contactless purchases using a relay setup. A less likely scenario involves a proximity relay attack against a card still in the owner's possession, which would require sustained NFC proximity and a live relay during the transaction.
For cardholders, the recommended precaution is to physically destroy expired and replacement cards. This includes cutting through the chip multiple times, making additional cuts to disrupt the contactless antenna, and damaging the magnetic stripe before disposal. Additionally, reporting a lost expired card is advised rather than assuming it is inert. However, the primary responsibility for addressing this vulnerability lies with payment networks, terminal implementers, and card issuers to ensure that expiration data is integrity-protected and that authorization systems correctly reject retired card credentials.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.