Zombie Card Attack Exploits Contactless Payments for POS Terminals

Executive Summary Researchers at the University of Massachusetts Amherst report the technical details of an attack vector that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale terminal reads over near-field communication, without breaking any of the card’s cryptography. The attack, which the researchers named Zombie Card, requires physical…

Read More

When Your Vendor’s Vendor Goes Down: What a Logistics Incident Teaches Retailers About Fourth-Party Risk

A Single Incident Ripples Across Industries In late July, a major global logistics and shipping provider was hit by a cyberattack that disrupted warehouse operations across Europe. The company, which operates more than 1,700 facilities in 170 countries, notified affected customers in early August that several European warehouses were unable to ship stored goods. Some…

Read More

TheHatman Listing Major Retail and Hospitality Azure/Entra Records on Dark Web Forum

Executive Summary A threat actor known as TheHatman is currently selling massive internal employee directories belonging to major retail entities on Breached cybercrime forum. Starting on 31 July, TheHatman advertised data dumps allegedly downloaded directly from the organizations’ Azure and Entra portals utilizing compromised credentials. The campaign impacts multiple global retail and hospitality organizations, with the threat…

Read More

DOUBLECUP ClickFix Loader Delivers CountLoader and DeviceManager RATs

Executive Summary A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns. The service enables operators to configure malicious lure pages that instruct victims to copy and execute commands from fake verification prompts. DOUBLECUP retrieves hidden code from a steganographic PNG cached by the victim’s browser…

Read More

The Missing Owner: Why Every AI Agent Needs Governance, Not Just Guardrails

Overnight, a retailer’s support agent issues hundreds of refunds. At a hospitality group, a guest-services agent comps dozens of rooms across the portfolio and reinstates loyalty points to match. Every action clears a standard business rule: valid order or reservation, plausible reason, amount under the threshold that would route it to a human. By morning,…

Read More