<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Payment Security on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/payment-security/</link><description>Recent content in Payment Security on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 19 Aug 2026 13:17:29 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/payment-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Zombie Card Attack Revives Expired Credit Cards for Contactless Payments</title><link>https://hackingpassion.com/zombie-card-expired-cards/</link><pubDate>Wed, 19 Aug 2026 13:17:29 +0200</pubDate><guid>https://hackingpassion.com/zombie-card-expired-cards/</guid><description>&lt;p>Expired credit cards still paid at the checkout. Researchers spent &lt;strong>$500&lt;/strong> on one, then &lt;strong>$2.79&lt;/strong> in a shop. The cards had already been handed in for a replacement, and the account behind them stayed open.&lt;/p>
&lt;p>A payment card sells one promise on its front. The date printed there is the day the card stops working. Shops rely on it, banks rely on it, and you rely on it when you drop an old card in a drawer instead of destroying it. Researchers at the &lt;strong>University of Massachusetts Amherst&lt;/strong> took that promise apart. Their finding is that &lt;strong>the date is not a property of the card at all&lt;/strong>. The date is a policy, checked in different places by parties that never compare notes, and a card that is past it can still pay.&lt;/p></description></item></channel></rss>