In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
CISA mandates federal agencies prioritize patching CVE-2025-62593, an actively exploited code injection flaw in Ray-Project, weaponized by the RondoDox botnet using 174 distinct exploits against edge devices Wiz's autonomous AI agent discovered and exploited a critical GitHub Actions workflow vulnerability in Snowflake's public repo, though GitHub clarified the vulnerable code was human-authored, not AI-generated Medusa ransomware affiliates are rapidly exploiting vulnerabilities in Fortra GoAny
Analysis
TL;DR
- CISA mandates federal agencies prioritize patching CVE-2025-62593, an actively exploited code injection flaw in Ray-Project, weaponized by the RondoDox botnet using 174 distinct exploits against edge devices
- Wiz's autonomous AI agent discovered and exploited a critical GitHub Actions workflow vulnerability in Snowflake's public repo, though GitHub clarified the vulnerable code was human-authored, not AI-generated
- Medusa ransomware affiliates are rapidly exploiting vulnerabilities in Fortra GoAnywhere and BeyondTrust, with over 500 critical infrastructure organizations compromised and an evolving evasion toolkit including Minidump credential theft
- Academic researchers demonstrated the "Zombie Card" attack, bypassing cryptographic checks on contactless Visa payments by using a smartphone relay to alter expiration dates fed to POS terminals
- Crypto4A became the first company globally to achieve FIPS 140-3 Level 3 validation for a hardware security module supporting all NIST-approved post-quantum cryptographic algorithms
Why It Matters
This roundup underscores the accelerating convergence of AI capabilities with offensive cybersecurity operations, as autonomous AI agents now successfully identify and exploit complex infrastructure vulnerabilities—a capability that will only grow more sophisticated. The persistent exploitation of supply chain and third-party software vulnerabilities (GoAnywhere, BeyondTrust, Ray-Project) highlights the critical need for proactive threat monitoring and rapid patch management in enterprise environments. Meanwhile, the emergence of post-quantum cryptography certification and novel payment card attacks signals that both defensive and offensive security landscapes are undergoing rapid transformation.
Technical Details
- CVE-2025-62593 (Ray-Project): A severe code injection vulnerability in the Ray distributed computing framework, added to CISA's Known Exploited Vulnerabilities catalog after active exploitation by RondoDox, a Mirai-inspired botnet employing 174 distinct exploit vectors against edge devices
- Wiz autonomous AI agent: An AI-driven security tool that successfully identified a critical GitHub Actions workflow vulnerability in Snowflake's public repository, chaining it to gain unauthorized access to internal Jira tickets; GitHub confirmed the vulnerable code was human-authored
- Medusa ransomware evasion toolkit: Affiliates now utilize Minidump for credential theft and Interactsh dynamic URLs to verify successful network exploitation, targeting vulnerabilities in Fortra GoAnywhere and BeyondTrust products across critical infrastructure
- Zombie Card attack: A relay-based attack exploiting a communication gap between POS terminal hardware and issuing banks, using a smartphone to modify the expiration date transmitted to the terminal, bypassing cryptographic validation on select Visa cards
- Crypto4A QASM module: The first HSM to achieve FIPS 140-3 Level 3 validation with support for all NIST-approved post-quantum cryptographic algorithms, providing tamper-resistant key storage against future quantum computing threats
Industry Insight
- Organizations must treat autonomous AI security tools as both defensive assets and potential threat multipliers; the Wiz-Snowflake incident demonstrates that AI agents can now perform complex, multi-step exploitation chains that previously required skilled human operators
- The Medusa ransomware advisory signals an urgent need for inventory and patch management of Fortra GoAnywhere and BeyondTrust products, particularly for critical infrastructure operators who are primary targets
- The Zombie Card attack reveals that payment ecosystem security depends on assumptions about communication integrity between terminals and issuing banks; card networks and merchants should audit relay attack surface and implement transaction binding mechanisms
- Crypto4A's post-quantum HSM certification marks a practical milestone for organizations planning quantum-resistant cryptography migration, providing a validated hardware foundation for key protection in the post-quantum era
Disclaimer: The above content is generated by AI and is for reference only.