Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

Posted on September 12, 2025September 12, 2025 By CWS

SEC Seek the advice of, a cybersecurity consulting agency underneath Eviden, says cost options firm KioSoft took a very long time to deal with a severe vulnerability affecting a few of its NFC-based playing cards.

KioSoft manufactures unattended self-service cost machines, together with for laundromats, arcades, merchandising machines, and automotive washes. The corporate relies in Florida and has workplaces in seven international locations around the globe. Its web site claims it has deployed over 41,000 kiosks and 1.6 million cost terminals throughout 35 international locations. 

SEC Seek the advice of researchers found again in 2023 that a few of KioSoft’s stored-value playing cards — digital wallets that prospects reload to be used at particular cost terminals — are affected by a vulnerability (CVE-2025-8699) that may be exploited without cost stability top-ups. The hack depends on the truth that the stability is saved domestically on the cardboard quite than a safe on-line database. 

The impacted playing cards recognized by SEC Seek the advice of relied on MiFare Traditional NFC card know-how, which is understood to have vital safety points.

Constructing on the identified MiFare card vulnerabilities and analyzing how information is saved on the playing cards, SEC Seek the advice of researchers managed to learn information from the cardboard and write information on the cardboard, enabling them to “create cash out of skinny air”. A hacker can improve the cardboard’s stability to as much as $655, however the course of may be repeated, SEC Seek the advice of’s Johannes Greil advised SecurityWeek.

An attacker can conduct an assault utilizing a {hardware} instrument such because the Proxmark, which is designed for RFID safety evaluation, analysis and growth. The attacker additionally must have some data of the MiFare card vulnerabilities to hold out a hack, Greil defined.

SEC Seek the advice of printed an advisory describing its analysis this week. The corporate has made obtainable an in depth timeline of its interplay with KioSoft, revealing that it took the seller effectively over a yr to launch a patch.

The safety agency first contacted KioSoft in October 2023, however the vendor was unresponsive till the CERT Coordination Middle on the Software program Engineering Institute of Carnegie Mellon College turned concerned. Commercial. Scroll to proceed studying.

SEC Seek the advice of claims to have despatched many requests for a standing replace since October 2023, with many going unanswered. The timeline exhibits that the seller has requested a number of extensions to the disclosure deadline, and in the end knowledgeable the safety agency {that a} firmware patch was launched in the summertime of 2025. The seller indicated that new {hardware} would even be rolled out sooner or later. 

KioSoft refused to offer model numbers of impacted and patched releases, arguing that affected prospects can be privately notified, the safety agency stated. Whereas KioSoft’s merchandise are extensively used, the seller advised SEC Seek the advice of that almost all of its options don’t use the weak MiFare card know-how.

SEC Seek the advice of now not has entry to the terminals it initially carried out its analysis on and it couldn’t confirm the seller’s patch. 

KioSoft has not responded to SecurityWeek’s request for remark. 

Associated: eSIM Hack Permits for Cloning, Spying

Associated: Main Backdoor in Thousands and thousands of RFID Playing cards Permits Instantaneous Cloning

Security Week News Tags:Card, Firm, Hack, Infinite, Patch, Payment, Security, System, TopUp, Vendor, Year

Post navigation

Previous Post: Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects
Next Post: Microsoft Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

Related Posts

Security Theater or Real Defense? The KPIs That Tell the Truth Security Week News
Production at Steelmaker Nucor Disrupted by Cyberattack Security Week News
SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance Security Week News
Agentic Security Firm 7AI Raises $130 Million Security Week News
Sophisticated Koske Linux Malware Developed With AI Aid Security Week News
In Other News: PQC Adoption, New Android Spyware, FEMA Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In Other News: PromptPwnd Attack, Small macOS Bounties, Chinese Hackers Trained in Cisco Academy
  • New Research Details on What Happens to Data Stolen in a Phishing Attack
  • New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale
  • New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users
  • Gladinet CentreStack Flaw Exploited to Hack Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In Other News: PromptPwnd Attack, Small macOS Bounties, Chinese Hackers Trained in Cisco Academy
  • New Research Details on What Happens to Data Stolen in a Phishing Attack
  • New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale
  • New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users
  • Gladinet CentreStack Flaw Exploited to Hack Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark