Cybersecurity threats are increasingly crossing the boundaries between financial systems, telecommunications infrastructure, software development and artificial intelligence.
Three recent developments highlight this changing threat landscape: research demonstrating how expired contactless payment cards could potentially be revived, a sophisticated intrusion involving telecommunications infrastructure, and renewed debate about the role of AI in software vulnerabilities.
Together, these incidents reinforce one important message: organizations cannot depend on assumptions about how technology is supposed to behave. Security controls must be continuously tested against how systems can actually be abused.
1. Zombie Card Research Exposes Weaknesses in Contactless Payments
Researchers from the University of Massachusetts Amherst demonstrated a technique they called the Zombie Card attack, showing that certain expired contactless payment cards could potentially be made to appear valid to a payment terminal.
The research identified a gap between the expiration information evaluated by the point of sale terminal and the information protected by the card’s cryptographic mechanisms.
The technique involves manipulating information transmitted through near field communication while preserving the cryptographic elements that the terminal and issuer continue to validate.
The research was evaluated across multiple payment environments, card networks, terminals and issuing banks. The results demonstrate why security cannot rely solely on strong cryptography when different components of a transaction enforce security policies independently.
For financial institutions and retailers, this is an important reminder that payment security must be evaluated end to end.
Organizations should consider:
• Secure payment protocol validation
• POS terminal security testing
• NFC and contactless transaction testing
• Fraud detection and transaction monitoring
• Strong lifecycle controls for payment credentials
• Continuous assessment of legacy payment infrastructure
• Independent penetration testing of payment environments
The lesson is broader than payment cards. A system can have strong cryptographic protection and still contain weaknesses at the points where different security controls interact.
2. Telecom Infrastructure Remains a High Value Target
Another recent incident involving T Mobile highlights the difficulty of defending large telecommunications environments against sophisticated intrusions.
Security teams reportedly discovered suspicious infrastructure associated with a China linked campaign inside the company’s network environment. The investigation eventually led security personnel to physically disconnect a network connection at a data center to eliminate the suspected access path.
The incident demonstrates an important principle of incident response: when an active threat cannot be confidently contained through logical controls, physical isolation may become necessary.
Telecommunications companies operate highly interconnected environments containing routing systems, network management platforms, customer infrastructure and critical communications services.
A compromise of network infrastructure can potentially provide attackers with opportunities for surveillance, persistence or lateral movement.
Telecommunications organizations should therefore prioritize:
• Network segmentation
• Zero Trust architecture
• Continuous network monitoring
• Privileged access management
• Infrastructure asset discovery
• Hardware and firmware validation
• Threat hunting
• Secure remote administration
• Incident response exercises
• Physical and logical access controls
The incident also demonstrates the importance of knowing exactly what devices are connected to critical infrastructure.
3. AI Is Changing the Software Security Conversation
The third development involves the growing debate around AI assisted software development.
AI coding assistants and automated development tools are now deeply integrated into modern software engineering. They can help developers write, review and modify code at unprecedented speed.
However, determining whether AI directly created a vulnerability can be complicated.
Recent reporting around a vulnerability in a public GitHub repository initially raised questions about whether AI generated code was responsible. Subsequent clarification indicated that the vulnerable code itself had been written by a human engineer, although AI tools were involved elsewhere in the development and security workflow.
This distinction matters.
Organizations should not treat AI as either automatically responsible for software defects or automatically trustworthy.
Instead, AI generated and AI assisted code should pass through the same, or stronger, security controls applied to traditionally developed software.
Recommended controls include:
• Secure code review
• Static Application Security Testing
• Dynamic Application Security Testing
• Software Composition Analysis
• Secret scanning
• Dependency monitoring
• Software Bill of Materials management
• Threat modeling
• AI generated code validation
• Security testing throughout CI/CD pipelines
GitHub’s recent service incidents also demonstrate that AI powered development infrastructure is becoming increasingly important to software delivery. GitHub’s status records show multiple incidents affecting Copilot and other development services during August 2026.
As organizations increase their dependence on AI coding agents, security teams need visibility into both the code and the AI systems participating in the development process.
What These Incidents Have in Common
At first glance, payment cards, telecom infrastructure and AI assisted software development appear unrelated.
They are not.
All three demonstrate the risks created when organizations rely on assumptions about trusted systems.
A payment terminal may trust information that is not adequately bound to authenticated data.
A network may contain infrastructure that security teams did not initially recognize as malicious.
A development organization may assume that AI assisted code has been sufficiently reviewed when traditional security validation has not been completed.
These are all examples of security gaps emerging at the boundaries between systems.
Modern cybersecurity therefore requires more than protecting individual components. Organizations need to understand how systems interact, where trust is established and where security decisions are delegated.
How Organizations Can Reduce These Risks
Organizations across industries should consider adopting a layered security strategy that includes:
• Continuous attack surface management
• Regular penetration testing
• Security architecture reviews
• Zero Trust principles
• Identity and access management
• Continuous vulnerability management
• Secure software development practices
• AI security assessments
• Third party risk management
• Security monitoring and threat detection
• Incident response planning
• Compliance driven security controls
Security testing should also reflect real world attack scenarios rather than simply checking whether individual components meet baseline security requirements.
Industries Most Affected
These developments are particularly relevant to:
• Banking and financial services
• Payment processors and fintech companies
• Retail and e commerce organizations
• Telecommunications providers
• Technology and SaaS companies
• Healthcare organizations
• Manufacturing enterprises
• Government agencies
• Critical infrastructure operators
• Organizations adopting AI assisted software development
For these industries, a vulnerability in one component can potentially affect customers, operations, sensitive information and regulatory obligations.
Conclusion
The latest cybersecurity developments show that attackers and security researchers are increasingly focusing on the connections between technologies rather than isolated systems.
A payment protocol can contain an unexpected trust gap. A telecommunications network can be compromised through infrastructure that appears legitimate. AI assisted development can introduce new questions around software accountability and validation.
The answer is not to avoid new technology.
The answer is to secure it properly.
Organizations should continuously test their technology environments, validate security assumptions, monitor for abnormal activity and build security into the development and deployment lifecycle.
Cybersecurity must evolve alongside technology. As financial systems, telecommunications networks and AI powered applications become more interconnected, security teams need deeper visibility and stronger controls across the entire digital ecosystem.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
Based on the risks highlighted in these developments, COE Security can also help financial institutions, payment providers and retailers assess payment and transaction security, telecommunications organizations strengthen network and infrastructure security, and technology companies secure AI assisted software development environments.
Our security services can support organizations with application security assessments, infrastructure security reviews, penetration testing, vulnerability management, third party risk assessments, AI security validation, secure development practices, threat detection and compliance readiness.
COE Security helps organizations identify weaknesses before attackers can exploit them, strengthen security controls and build resilient digital environments aligned with their business and regulatory requirements.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article