← BACK TO FEED
ransomwareDDoSSalt Typhoonpost-quantum cryptographycontactless payments

Weekly Roundup: Zombie Cards, Salt Typhoon Scissors, and GitHub's AI Blame Deflection

This week's cybersecurity roundup covers a range of notable incidents and developments, including CISA mandating fixes for an actively exploited Ray vulnerability, T-Mobile physically cutting a router cable to halt a Chinese state-sponsored intrusion, and researchers demonstrating a "Zombie Card" attack that enables contactless payments using expired Visa cards. Other highlights include a critical GitHub Actions vulnerability discovered by an AI agent (though the flawed code itself was human-written), Medusa ransomware affiliates exploiting GoAnywhere and BeyondTrust vulnerabilities across 500+ critical infrastructure organizations, and data breaches affecting Alation and Japan's Sakura Internet. Rounding out the week, Canadian firm Crypto4A achieved a landmark FIPS 140-3 Level 3 certification for post-quantum cryptography hardware.

A grab-bag of stories that deserve more than a footnote.

CISA Flags Actively Exploited Ray Vulnerability

Federal civilian agencies have been told to patch CVE-2025-62593, a code injection flaw in Ray-Project Ray, after it turned up in CISA's Known Exploited Vulnerabilities catalogue. The threat is real: BitSight spotted it being abused by RondoDox, a Mirai-derivative botnet armed with 174 separate exploits targeting exposed edge devices. Yes, 174.

GitHub: The Bug Was Human, Actually

Wiz built an autonomous AI agent that found and exploited a critical GitHub Actions workflow vulnerability in a public Snowflake repository, ultimately reaching internal Jira tickets. Early reporting suggested GitHub Copilot wrote the dodgy code. GitHub has since told SecurityWeek that no, a human wrote it. Whether that makes anyone feel better is unclear.

Threema Gets DDoS'd

Encrypted messaging app Threema took a beating from sustained DDoS attacks aimed at both its own infrastructure and its colocation partner. The company scrambled to deploy upstream traffic filtering to absorb the onslaught before it knocked everything offline.

Evooo1Bot: More Than Just a DDoS Tool

FortiGuard Labs is tracking a modular Linux botnet called Evooo1Bot that exploits over a dozen known CVEs against internet-facing devices. It goes well beyond basic DDoS: there's an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module that turns compromised hosts into persistent proxy nodes. Tidy little package.

T-Mobile Stopped Salt Typhoon With Scissors

Possibly the most satisfying incident response story in recent memory. When Chinese state-sponsored group Salt Typhoon was actively inside T-Mobile's network in 2024, security staff at a Bellevue data centre reportedly picked up a pair of scissors and physically cut the cable on a compromised router. Sometimes the old ways work. T-Mobile was one of several major US carriers caught up in the broader Salt Typhoon espionage campaign.

TeamPCP Claims 73GB Haul from Alation

Data catalogue firm Alation confirmed an unauthorized breach of its internal network. Hacking outfit TeamPCP is claiming credit, saying they walked off with 73 gigabytes of data. Alation hasn't disputed that an intrusion occurred.

Sakura Internet Breach Hits 1.3 Million Records

Japanese hosting provider Sakura Internet found a serious data breach in its sales management system while investigating what appeared to be a separate, unrelated malware incident on a small number of rental servers. The breach may have exposed contract and membership data for up to 1.36 million customers. Finding one problem while looking for another is a particularly grim kind of surprise.

Medusa Ransomware Keeps Busy

A joint advisory from CISA, the FBI, and HHS warns that Medusa ransomware affiliates are actively exploiting vulnerabilities in Fortra GoAnywhere and BeyondTrust. The group has updated its toolkit to include Minidump for credential harvesting and Interactsh URLs to confirm successful exploitation. Over 500 critical infrastructure organisations have been hit to date, according to the advisory.

Zombie Card Attack Revives Expired Visa Cards

Researchers have demonstrated a neat trick: using a smartphone relay to feed a modified expiration date to a contactless payment terminal, enabling completed transactions with physically expired Visa cards. The gap being exploited sits between the POS terminal's local validation and what the issuing bank actually checks. It doesn't work on Mastercard, Amex, or Discover, and not all banks are vulnerable. Visa has not commented.

Post-Quantum HSM Clears FIPS 140-3 Level 3

Canadian firm Crypto4A has become the first company anywhere to achieve FIPS 140-3 Level 3 validation for a hardware security module supporting all NIST-approved post-quantum algorithms. Their QASM module is designed to protect cryptographic keys against future quantum-enabled attacks. A niche win, but a meaningful one.

READ NEXT
LockBit Claims US Bank Scalp With September Leak DeadlineCl0p Names 40+ Windchill Victims — Shell, Philips, Fiserv Among Those Called OutNearly 2,000 Hacked WordPress Sites Are Powering a Surprisingly Sophisticated Criminal Operation