ID scanning provider used by Hertz and GameStop is now under FBI investigation
A hot potato: A dark-web service that claimed to sell scans of more than 153 million US and Canadian driver's licenses has gone offline after Krebs on Security identified it. Before disappearing, the site offered ID images that appeared to include standard scans as well as infrared and ultraviolet versions used in document-verification systems. This development points to a potentially far-reaching compromise of the systems businesses use to verify physical IDs.
A Bluetooth glitch exposed AliExpress's hidden audio fingerprinting
A hot potato: As cookies become a less reliable way to track people online, AliExpress may be showing how far companies will go to fill that gap. Researchers found code on the site's homepage that ran silent audio processes in the browser. Tied to Alibaba's security systems, the scripts tap a device's own audio hardware to generate a signal and measure the tiny, device-specific ways it comes back – producing something close to a fingerprint that doesn't need a single cookie to work. It's the kind of tracking a user would likely never notice.
"Zombie card" exploit uses two smartphones to rewrite credit card expiration data
WTF?! Credit cards aren't meant to last forever, but a team of researchers just found a way to keep expired ones alive for a little longer than intended, and not for the cardholder's benefit. Not every card is affected, but the flaw sits deep enough in how contactless payments are verified that exploitation isn't just theoretical.