Nextron Systems GmbH: Discovered Malicious Rust Crate
Nextron Systems GmbH's Research Team initially discovered and reported the malicious proc-macro1 crate to the Rust Security Response Team. Their analysis detailed…
Cybersecurity companies, vendors and market players.
Nextron Systems GmbH's Research Team initially discovered and reported the malicious proc-macro1 crate to the Rust Security Response Team. Their analysis detailed…
ZoomEye, a cyberspace mapping service, is used by threat actors to find poorly protected PLCs exposed to the internet. This aids in…
Israeli cybersecurity company Dream detailed a near-autonomous attack targeting government entities in Asia, reportedly Taiwan. The attack used AI agents like OpenClaw…
Mastercard's EMV contactless kernel (Kernel 2) includes a consistency check between the two expiry representations, causing a mismatch to be treated as…
American Express's EMV contactless kernel (Kernel 4) binds the expiration date into static data covered by offline data authentication, producing a hash…
Discover's EMV contactless kernel (Kernel 6) uses Combined Dynamic Data Authentication, which binds card-returned TLV objects into the verified transaction hash. Modified…
EMVCo, the body that manages EMV specifications, has not published any advisory or specification bulletin regarding the Zombie Card attack as of…
SumUp Solo and SumUp Plus card readers were used in the Zombie Card attack testbed. The terminals did not implement EMV's optional…
Researchers at the University of Massachusetts Amherst, including Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza, demonstrated the Zombie Card attack…
Visa's EMV contactless kernel (Kernel 3) is vulnerable to the Zombie Card attack, which allows expired cards to be revived for transactions…