Risky Bulletin: Expired cards can be used for new transactions
In other news: Iranian hackers shut down UK power plant; Lazarus hacks South Korea's Presidential Office; Android malware infects cars.
This newsletter is brought to you by Push Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
A team of academics from the University of Massachusetts Amherst have developed an attack that can revive old expired contactless cards to perform new (illegal) transactions.
The attack exploits the fact that NFC card data is not fully encrypted when making a payment and some parameters can be modified without breaking the card's digital hash/signature.
The researchers created a rig that intercepts transaction data through an NFC Man-in-the-Middle attack, updates the expiration date, and relays the modified payment to a Point-of-Sale (POS) terminal.

It's a simple attack that nobody thought to investigate because everyone assumed banks are enforcing the expiration date check and would catch any modifications that do not align with their backend systems.
In reality, the research team says that banks typically leave this check to the POS terminal device where the transaction occurs and trusts its decision.
The study found that three of the four major card payment providers—Mastercard, American Express, and Discover—were using POS terminals where modifying the expiration date would result in a card hash/signature mismatch that caused the transaction to fail.
On Visa terminals, the attack worked, and it also wasn't caught on by five banks on their backends—the number of banks the researchers used for their study.
The attack does not require specialized hardware to perform, and uses basic NFC emulators and POS terminals you can purchase online.
The only "problematic" condition was that attackers had some way of getting their hands on old expired cards. These could be collected from the trash, or stolen from users who failed to destroy their old cards.
As such, the main recommendation of the study was not necessarily that banks and Visa need to do a better job coding their backends and POS terminals (which they should be doing anyway), but that users need to take scissors to their old cards and chomp them into tiny bits once they expire.
Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Dmitri Alperovitch at the helm!
Breaches, hacks, and security incidents
Iranian hackers shut down UK power plant: A small-scale UK power plant had to shut down operations for four days last month after a cyberattack from Iranian hackers. British officials refused to disclose which power plant was affected. According to The Telegraph, the attack was carried out by the same hackers who breached water utilities in the US. [The Telegraph]
Lazarus hacks South Korea's Presidential Office: North Korean espionage group Lazarus has hacked South Korea's Presidential Office in February this year. The hack was part of a broader campaign that racked up more than 100 victims by April. Other victims included universities, police departments, news agencies, and hospitals. South Korean authorities are still investigating the breaches and have not released any details about how the hackers got in. [Munhwa] [h/t DLL]
SFR telco breach: Hackers have stolen customer data from French telecom SFR in a security breach last month. More than 2.1 million customers are believed to have been affected. Stolen data includes names, postal addresses, phone numbers, and contract and connection details. For some customers data such as IP addresses and equipment details was also exposed. [FrenchBreaches // The Local] [h/t D. vH]
SickKids data breach: Hackers have stolen the personal data of employees of SickKids, a Toronto-based pediatric hospital for treating sick children with difficult diseases. The hospital says no patient data was exposed. SickKids blamed the incident on a "vulnerability in a third-party software application." The hospital will provide 24 months of credit monitoring and identity protection services to all affected employees. [SickKids statement // CityNews Toronto]
Apollo breach: Hackers have stolen customer data from private equity company Apollo Global Management. The company confirmed a data breach in a letter to the California attorney general last week. It says hackers breached Apollo's cloud systems using a social engineering attack at the start of July. The hack is part of a broader campaign that targeted US investment and Wall Street firms last month. [CyberScoop // California OAG]
Maya Protocol crypto-heist: Hackers have stolen $1.7 million worth of crypto-assets from the Maya Protocol. The attacker allegedly exploited the protocol's anti-theft defenses to trick the platform into unwanted loans. Investigators believe the hacker used an AI tool to chain exploits for six smaller unrelated bugs. [Maya Protocol // Cryptopolitan]
Suspected ReliaQuest hack: The ShinyHunters group claimed in a dark web listing that they hacked security firm ReliaQuest. They haven't provided any proof, though. Yet. The group seems to have a beef with the company, claiming that some of its recent reports were inaccurate. [DataBreaches.net]
"On its dedicated leak site, ShinyHunters named ReliaQuest, LLC, but has offered no proof of claims at all. The listing merely says, in part, “This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away.”"
AI, general tech, and privacy
Uber fined €825 million in the Netherlands: The Dutch Data Protection Authority has fined Uber €825 million for unfair driver account bans. The agency says Uber disabled driver accounts using automated systems, with no human review, and without informing drivers of the reason. The fine is the second-largest data protection fine imposed on a company in the EU. Meta was fined €1.2 billion in Ireland in 2023. [Autoriteit Persoonsgegevens]
TikTok settles with the DOJ for $400m: The US Justice Department and TikTok have settled a lawsuit and the company has agreed to pay a $400 million penalty for breaking US child privacy laws. The penalty also covers infractions committed by Musical.ly, which ByteDance acquired in 2017 and merged into TikTok. The settlement represents one of the largest recoveries ever obtained in a COPPA investigation. [DOJ]
Microsoft prepares to change code-signing infrastructure: Microsoft has notified developers that their apps will break in the coming weeks when it will update its code-signing infrastructure. The company plans to move to new servers that will use stronger signing algorithms and post-quantum cryptography (PQC). The move is expected to complete by mid-October. [Microsoft]
CIA helped Steve Jobs: A new book claims the CIA bailed out Steve Jobs' NeXT company in the 80s, when it was having financial issues. [WSJ // Hachette]
Yandex uses AI to hide military bases: Russian company Yandex is using generative AI to hide the location of Russian military bases on Yandex Maps.
Yandex, Russia's map service, tried to hide a Russian military site on satellite imagery, located near St Petersburg, by covering the imagery with a fake forest.
— Benjamin Strick (@BenDoBrown) August 18, 2026
The findings were made by Finnish broadcaster @yleuutiset. More below 👇 pic.twitter.com/eUx1Dbad2u
Government, politics, and policy
Nothing in this edition.
Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Push Security’s VP of Research Luke Jennings about how stronger authentication is pushing attackers towards the authorisation layer.
Arrests, cybercrime, and threat intel
Indian scammer arrested: The US has charged an Indian national for defrauding elderly Americans of almost $7.6 million via online and phone scams. Jay Sunilbharthi Goswami was arrested in Canada last week after fleeing the US following an initial court appearance. He was detained at the Toronto airport while trying to board a flight to Doha, Qatar. Goswami faces up to 20 years in prison. [DOJ]
Dutch crack Pixel phones: Dutch media is reporting that police managed to crack the locked Google Pixel smartphone of one of three murder suspects. It's unclear what methods they used, or if the phones were running really old software, but to keep an eye on. [Omroep Brabant]
Attacks grow in sophistication: New Zealand's cybersecurity agency says that while the number of security incidents have gone down in the second quarter of the year, attacks have grown in sophistication. Ninety-two of the 1,129 incidents reported in Q2 required specialist technical support. Scams and fraud were still the most reported incidents. [NZ NCSC]
Kriminal.ai: Security researchers have spotted a cybercrime service selling access to an cybercrime AI toolkit with no filters or guardrails. [ThreatDown]
FTP banners as DDRs: A malware campaign is using FTP server login banners as a dead-drop resolver system. The banners are text messages shown to users when connecting to an FTP server or host. Threat actors are hiding malicious commands inside the banners from where their malware can retrieve them after a successful infection. Attackers prefer the technique because it bypasses most security monitoring solutions. [SOCRadar]
SilverFox operations: The DomainTools security team has put out an interesting report on how the SilverFox MaaS continued to add new domains to its operation despite the arrests of some of its members and affiliates in late May, early June. [DomainTools // Risky Bulletin]
NoName057 launches physical threats: Pro-Kremlin hacktivist group NoName057 has recently switched from launching DDoS attacks to issuing death threats against foreign officials and their family members. [RealHackingHistory]
In the Spanish language Putinist propaganda channel aligned with NoName057(16) someone comments “they will go from walking calmly down the street to leaving in a panic, looking everywhere, checking their vehicle, their alarms, visiting computer technicians, … worried about their children”
— —>realhackhistory.org (@bsky.realhackhistory.org) August 23, 2026 at 3:33 PM
[image or embed]
BLACKNET-00 profile: Security researchers have published a profile of BLACKNET-00, a threat actor also known as the Infrastructure Destruction Squad. They categorize the group as highly promotional that can't live up to the claims it makes. Although it did develop a functional ransomware-builder and a Firebase database scanner, its SCADA hacking tools don't work. The group claims it's Chinese. [Ransom-ISAC]
New npm malware: Trend Micro researchers have found 14 malicious npm packages delivering a Linux implant named RedShell, which is part of RedC2, a hacking tool sold on hacking forums. [Trend Micro]

Git exposure: A new internet scan for .git files has found more than 28,000 internet-exposed Git repositories. [Intruder]
AWS keys with full admin access: Researchers who analyzed a cache of over 10,000 leaked AWS keys found that 768 of them had full admin access over the victims' networks. [Truffle Security]
Cluster of fake bank accounts: Security researchers have tracked down a cluster of more than 2,200 domains that mimic banks and financial institutions that seem to have been built on top of the same template and are likely part of a scam operation. [Allure Security]

Malware technical reports
Android malware infects cars: Security researchers have identified the first malware strain that infected the Android-based head unit of a modern smart car. The malware added the car to a botnet that engaged in ad fraud and proxy traffic. Kaspersky attributed this activity to the MoYu Group, a threat actor linked to the BADBOX botnet. [Kaspersky]
Hydra Remote: A new RAT named Hydra Remote is being advertised on hacking forums. [Marktsec]
6/ The infrastructure is designed for persistent remote operation as well. Advertised features include automatic reconnect, backup C2 hosts, multiple listener ports and per-installation communication keys. The builder produces an obfuscated x64 client for Windows 10/11.
— marktsec (@marktsec.bsky.social) August 21, 2026 at 1:46 PM
SynkLoader: Expel has discovered a new malware loader that was being used in hands-on-keyboard intrusions. One of its clever tricks was the use of a full-screen app to show a fake Windows lockscreen to phish a user's credentials. [Expel]
Sponsor section
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
APTs, cyber-espionage, and info-ops
Kimsuky adopts RMMs: After spending a decade developing and fine-tuning its own remote access trojans, one of North Korea hacking groups, Kimsuky, has been seen utilizing legitimate RMM tools as RAT replacements in some intrusions. [ENKI]
New FamousSparrow campaigns: A suspected Chinese APT group named FamousSparrow (Salt Typhoon, Earth Estries) has been using watering hole attacks via hacked websites to trick users into downloading and infecting themselves with a new version of the SparrowDoor backdoor. The campaign made victims in Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic. [Positive Technologies on Habr // Positive Technologies]
Vulnerabilities, security research, and bug bounty
Security updates: HP, Isolated-vm, Microsoft, Spring, TP-Link, Ubuntu.
AI drives POC surge: AI tools have contributed to a spike in public proof-of-concept code published online this year. Almost 18,000 POCs have been processed through mid-August, close to the 20,000 last year in full. Security firm VulnCheck says that while AI contributed to more POCs published online, it also contributed to a spike in fake or non-working exploits being posted online too. [VulnCheck]
[POC]
Entra ID RCE: Microsoft has patched a remote code execution bug in the Entra ID service. Microsoft rated the bug with a 10 severity score. The bug was discovered internally and was not exploited in the wild. Microsoft said the bug's initial advisory went out with an exploitation flag enabled by accident. [CVE-2026-69836]
CoSnitch vulnerability: Microsoft has patched a one-click vulnerability in Copilot that can be used to steal data from corporate environments. The bug was exposed by Copilot to the researchers during normal use. [Varonis // CVE-2026-24301]
SMAP bypass on Windows 11: Security researcher Youssef Charfeddine has discovered a way to bypass the Supervisor Mode Access Prevention feature on Windows 11. [Youssef Charfeddine]
Old ARPA domains can be hijacked: A security researcher going by the name of Lina has discovered that you can hijack old ARPA domains that were once used in some very ancient VoIP-system that attempted to route phone calls over the internet. Apparently, this wasn't as abandoned as initially thought, and the researcher ended up logging call traffic to a bunch of military bases. [Lina.sh]
Researcher tricks Apple's Find My People: A security researcher has tricked Apple into enrolling a malicious Linux machine into the Find My People network and used it to retrieve data from Apple's servers. This included the locations of a user's devices and the location data of friends who shared their location with that user's account. Not a really a major security hole, but still some clever research. [Zerotistic]
Fewer offsec blogs: An interesting observation from netbiosX, who noted a sharp fall in the number of offensive security blog posts over the past two years, as this knowledge is now being sold via private paid courses. [netbiosX]
Infosec industry
Threat/trend reports: Cisco, FitchRatings, Flashpoint, Forrester, Incogni, Kaspersky, NZ NCSC, Red Canary, and VulnCheck have recently published reports and summaries covering various emerging threats and industry trends.

New tool—hexcymatix: Security researcher Christopher Domas has released hexcymatix, a binary reverse engineering tool for extracting structural information from repeated byte patterns in binary files.
New tool—SquidC5: SquidSec has released SquidC5, an AI-native C5 (Command, Control, Cognitive, Collaborative, Coordination) teamserver for authorized red team and penetration testing.
Risky Business podcasts
In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about President Donald Trump's memo enlisting the US private sector to tackle cybercriminals.