Apple Tap-to-Pay Security Flaw Shown in Video: Locked iPhone Used in $10K Demo

Video shows how to steal $10,000 from locked iPhone in controlled setting -  9to5Mac

A new security demonstration has raised concerns about Apple’s payment ecosystem after a YouTuber showcased a potential vulnerability affecting tap-to-pay functionality on iPhones. The issue reportedly allows a locked device to be manipulated in a way that simulates a legitimate payment interaction, without requiring the phone to be unlocked or directly authorized by the user.

Apple has long promoted its ecosystem as highly secure, particularly when it comes to features like NFC-based payments and Express Transit Mode. However, the demonstration suggests that under specific conditions, an attacker could potentially exploit a “man-in-the-middle” style setup to trick an iPhone into processing a payment as if it were interacting with a real point-of-sale terminal.

In the video, the creator—working alongside cybersecurity researchers—shows how specialized hardware can intercept and relay NFC signals. The setup reportedly uses a device connected to a computer to mimic a payment terminal, effectively convincing the iPhone that a legitimate transaction is taking place. The demonstration includes a test scenario involving a locked device, raising questions about how such interactions are validated.

The exploit, according to the video, is based on a concept that has been known in cybersecurity circles for several years, though it has now been presented in a more practical, real-world context. It highlights how NFC-based systems, while convenient, can still be vulnerable to relay attacks if security layers are bypassed or misinterpreted.

While there is no indication of widespread real-world abuse, the demonstration has sparked renewed discussion about mobile payment security and the importance of layered protections. It also underscores the ongoing challenge for companies like Apple to balance convenience features such as tap-to-pay with evolving security threats in mobile ecosystems.

US warns of escalating Iranian cyberattacks on infrastructure

U.S. authorities have warned that Iranian-backed hacking campaigns targeting critical infrastructure have intensified following the escalation of regional hostilities.

According to a joint advisory issued by agencies including the FBI, National Security Agency and Cybersecurity and Infrastructure Security Agency, attackers are focusing on industrial control systems widely used across essential sectors.

Targets and Methods

The hackers are primarily exploiting:

  • Programmable Logic Controllers (PLCs)
  • SCADA systems (Supervisory Control and Data Acquisition)

These systems are critical for operating infrastructure such as:

  • Energy grids
  • Water and wastewater facilities
  • Government service systems

Attack techniques include:

  • Manipulating system display data
  • Extracting sensitive operational configurations
  • Interfering with real-time control processes

In several cases, the activity has already resulted in operational disruption and financial losses.

Strategic Intent

U.S. officials assess that the campaigns aim to create “disruptive effects” within the United States, signaling a shift from espionage toward potential sabotage.

The warning aligns with broader geopolitical tensions involving Iran and the United States, with threats extending to infrastructure targets both domestically and across the Gulf region.

Agencies Involved

The advisory was jointly issued by multiple agencies, including:

  • Federal Bureau of Investigation
  • National Security Agency
  • Cybersecurity and Infrastructure Security Agency
  • Environmental Protection Agency
  • Department of Energy
  • U.S. Cyber Command’s Cyber National Mission Force

Risk Implications

The targeting of industrial control systems is particularly concerning because:

  • Many are internet-exposed with weak security configurations
  • They often run legacy software with limited patching
  • Disruption can have physical-world consequences, not just digital impact

Outlook

The escalation indicates a broader trend:

  • Cyber operations are increasingly integrated into geopolitical conflict
  • Critical infrastructure is becoming a primary attack surface
  • Defensive readiness for industrial systems is now a national security priority

Organizations operating ICS/SCADA environments are likely to face heightened pressure to:

  • Harden network exposure
  • Implement real-time monitoring
  • Segment operational technology (OT) from IT systems

PIMCO weighs $14B debt deal for Oracle data center

PIMCO is in discussions with Bank of America to provide roughly $14 billion in debt financing for a major data center project led by Oracle in Michigan, according to Bloomberg.

If completed, the deal would position PIMCO as a key financial backer of Oracle’s Saline Township data center campus, a project tied directly to the growing demand for artificial intelligence and cloud infrastructure.

Financing Structure

The proposed funding may be structured using a Rule 144A bond offering, which allows:

  • Private placement of debt
  • Sales primarily to institutional investors
  • Faster execution compared to public bond markets

PIMCO is also expected to syndicate part of the debt, distributing exposure among multiple investors.

Strategic Context: AI Infrastructure Boom

The project reflects Oracle’s aggressive expansion into AI infrastructure. The company previously announced plans to raise up to $50 billion through a mix of debt and equity to fund:

  • Data centers
  • Cloud capacity
  • AI computing infrastructure

This Michigan facility is part of a broader industry trend where hyperscalers and enterprise cloud providers are scaling physical infrastructure to support:

  • AI model training
  • Inference workloads
  • High-performance computing

Investor Concerns

Despite strong demand, Oracle’s strategy has drawn scrutiny:

  • Rising debt levels
  • Negative free cash flow trends
  • Heavy capital expenditure commitments

Investors are closely monitoring whether these large-scale investments will translate into sustainable long-term returns.

Parallel Developments

The financing discussions follow:

  • A separate $16 billion financing effort involving data center developer Related Digital
  • The recent appointment of Hilary Maxson as CFO, signaling a stronger focus on financial discipline during this expansion phase

Market Implications

If finalized, the deal would:

  • Rank among the largest private debt financings for AI infrastructure
  • Reinforce the role of institutional investors in funding hyperscale data centers
  • Highlight the shift from traditional bank loans toward capital markets-based funding structures

Outlook

Oracle’s Michigan project illustrates a broader structural shift:

  • AI demand is driving unprecedented capital intensity
  • Financing models are evolving toward large-scale private credit and bond syndication
  • Tech firms are increasingly dependent on financial markets to sustain infrastructure growth

Execution risk remains tied to:

  • Cost overruns
  • Energy and resource constraints
  • Demand sustainability for AI services