Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Russia gas station equipment infected with malware, hacking illegally hundreds of millions of rubles
  • News

Russia gas station equipment infected with malware, hacking illegally hundreds of millions of rubles

Do Son January 24, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

According to threatpost, on January 21, the Russian Federal Security Service (FSB) found that hackers are implementing a fraud scheme of gas station equipment, designed to use malicious programs installed on electronic tanker to achieve a 3% reduction per gallon when pumping gasoline To 7% of the purpose, so that customers pay more than the actual amount of fuel purchased. Currently, FSB has arrested the author of the development of malicious programs and involved dozens of gas station employees involved in the fraud.

According to several media reports in Russia, the FSB arrested hacker Denis Zayev in Stavropol, Russia on Saturday, allegations that it has developed several malware programs and sold them to gas station employees for fraudulent consumer use. This malware is currently only found at gas stations in southern Russia.

At the trial, Zayev admitted that gas station employees had split up on the extra money that consumers had paid. In addition, according to FSB’s speculation, the fraud plan may have brought it “hundreds of millions of rubles (1 renminbi equals 8.99 rubles)”.

The FSB said malware cannot only display fake data on tankers but also allow gas station employees to reduce fuel consumption by 3% to 7% per gallon for customers pumping gasoline, as well as registering errors in cash registers and back-end systems. Even more subtle, Zayev’s malware obscures gas-related sales figures from petrol stations. As a result, inspectors and oil companies that remotely monitor gasoline stocks find it harder to detect fraud.

In recent years, hacker incidents for gas stations are not uncommon:

Back in 2014, New York State authorities accused 13 men of using Bluetooth-enabled skimmers to steal more than $2 million in southern U.S. consumers between 2012 and 2013.

In 2015, black hat presentations by researchers Kyle Wilhoit and Stephen Hilt underscored the growing danger of the Internet monitoring system in the United States. They warn that the exposed SCADA system could cause malicious personnel to launch a DDoS attack on the tanker, damaging the car’s engine by recording incorrect fill-in data and manipulating the tanker to provide diesel rather than lead-free gasoline.

Source: ThreatPost

Related coverage

  • CVE-2026-76460 (CVSS 10): Cisco ISE Vulnerability Exploited in the Wild
  • New Stealit Infostealer Abuses Node.js SEA Feature and Telegram C2 in Malware-as-a-Service Campaign
  • OpenAI Files Motion to Dismiss Apple Lawsuit
  • US secret military base is revealed due to tracking sports Strava application
  • Django Releases Security Patches to Address DoS and Permission Vulnerabilities
  • Linux Kernel Flaw (CVE-2023-0386) Actively Exploited for Root Privilege Escalation, PoC Available
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: Russia gas station

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106414CVSS 9.6
    Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106329CVSS 9.6
    Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106239CVSS 9.6
    Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-102322CVSS 9.6
    Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.