Zombie Card relay, T‑Mobile severs cable, GitHub AI bug find
Researchers demonstrated a ‘Zombie Card’ relay that lets expired Visa cards make contactless payments; T‑Mobile cut a router cable to halt a state‑linked intrusion; GitHub clarified a Wiz AI found a human‑written bug.
Researchers demonstrated a “Zombie Card” relay attack that can complete contactless payments using physically expired Visa cards. Separately, T‑Mobile’s cybersecurity staff cut a router cable in 2024 to stop an active intrusion attributed to the Chinese state‑linked group Salt Typhoon. An autonomous security agent from Wiz exploited a GitHub Actions workflow; GitHub clarified the vulnerable code was written by humans, not generated by an AI assistant.
Academic researchers who disclosed the Zombie Card technique showed a smartphone‑based relay can alter the expiration date sent to a point‑of‑sale terminal, causing the terminal to accept an expired Visa card. The attack exploits a communication gap between the local terminal and the issuing bank’s verification process. The method worked on some Visa cards in tests but did not appear effective against Mastercard, American Express or Discover, and it failed against many banks’ issuer checks. Visa has not replied to requests for comment.
The Zombie Card attack requires physical access to an expired Visa card and a relay setup that forwards and modifies data between the card and the terminal in real time. The researchers said the exploit changes only the expiration date field shown to the terminal and does not break the card’s cryptography. Transactions complete when the terminal accepts the altered data before the issuer rejects the payment.
In 2024, T‑Mobile operators at a Bellevue, Washington data center severed the network cable of a compromised router with scissors to isolate the device and halt an ongoing network breach. The intrusion has been attributed to Salt Typhoon and formed part of a broader campaign that targeted multiple major U.S. carriers. T‑Mobile’s operators cut the connection after detecting active access to the device, with the intent of containing and removing the attacker’s foothold.
The Wiz incident involved an autonomous agent that identified and chained a misconfiguration in a public GitHub Actions workflow in a Snowflake repository. The agent used the workflow weakness to access internal Jira tickets at the affected company. Initial accounts attributed the vulnerability to a code assistant, but GitHub clarified the snippet responsible was authored by humans rather than generated by Copilot.
Security teams and platform operators are reviewing issuer validation logic for contactless payments, containment options for critical network devices, and controls for CI/CD workflows and code‑assistance tools to reduce the risk of similar incidents.








