vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard cryptographic checks. The attack, dubbed "Zombie Card," requires a man-in-the-middle relay and a card that… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
threat-intel Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Researchers at Hunt.io have uncovered a campaign targeting over 14,500 Dahua IP cameras, leveraging credential attacks and two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) to gain unauthorize… The Hacker News · Aug 19, 2026 High CVE-2021-33044CVE-2021-33045CVE-2024-39943UKRUcredential attackauthentication bypassp2p
threat-intel Ghost Tap : une fraude NFC signalée depuis Pattaya This article details a case in Pattaya, Thailand, where a reader of ZATAZ discovered a NFC-based banking fraud. The incident highlights a technique called ‘Ghost Tap,’ where a compromised device relays NFC communications… ZATAZ · Aug 13, 2026 Medium THnfcfraudrelay
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
vulnerability Siemens SIPROTEC 5 Using DIGSI5 Protocol This CISA advisory details a vulnerability in Siemens SIPROTEC 5 devices, specifically utilizing the DIGSI5 protocol, that allows authenticated users to upload arbitrary files. This could lead to denial-of-service condit… CISA Advisories · Jun 23, 2026 High CVE-2025-40808relayprotocoldenial of service