DNYUZ
No Result
View All Result
DNYUZ
No Result
View All Result
DNYUZ
Home News

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

August 31, 2026
in News
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has started working to raise the alarm, not just about overlooked ATM flaws, but about how that same software used in other industries can introduce weaknesses in an array of critical systems.

At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro’s integrity checks and gain full access to encrypted devices.

Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf’s Vynamic Security Suite. But CryptoPro is also sold as a security solution for other embedded-device makers, as well as big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries.

“ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that,” Burch says. “From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way and then there’s limited technical insight—bugs can get overlooked or they don’t get addressed.”

CryptWare managing director Uwe Saame tells WIRED that the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. Burch says the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities he found. While CryptoPro does not seem to publicly release update notes, Burch says he believes that the company distributed information about the patches to its customers.

Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED in a statement that only two of the nine vulnerabilities are relevant to Diebold Nixdorf’s Vynamic Security Hard Disk Encryption, the system where the ATM maker uses CryptoPro software. Jacobsen says that Diebold Nixdorf issued fixes related to those two bugs in December, but that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.

In ATMs, embedded devices, and enterprise security more broadly, the challenge of the software supply chain comes from all of the steps to actually apply fixes in the world. As in this case, a developer has to release a patch, then companies that implement the product in their own software need to develop a tailored fix, and then customers need to actually hear about and install that patch—which can be difficult for systems that are running in the field or can’t easily be paused and updated.

Speaking generally about this challenge, Jacobsen, the Diebold Nixdorf spokesperson, says that “when a security issue is identified, Diebold Nixdorf assesses the impact, identifies affected products and configurations, and develops any needed updates through our product security and engineering processes. We then notify impacted customers and provide updates through standard software distribution channels, including the Global Security Portal where applicable. For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes.”

Security researchers have warned for decades about the danger of relying on “security through obscurity” by trying to hide software from view or keep it locked away. And, as a result of this work, internet-of-things manufacturers and those in critical industries like the financial sector and medical device manufacturing have made some progress on transparency and promoting patch adoption. But Burch points out that as AI systems make it easier to evaluate software and find vulnerabilities—even for researchers or attackers who don’t have granular expertise in a given area—it is more pressing than ever to shed light on niche security products.

“AI really blows away the obscurity model,” Burch says. “You don’t need to fully understand how something works anymore to move forward and potentially have a big impact.”

The post ATM Flaws Reveal Key Weaknesses in the Software Supply Chain appeared first on Wired.

Testosterone treatment? Here’s a better idea.
News

Testosterone treatment? Here’s a better idea.

by Washington Post
August 31, 2026

Leonard Sax is the author of “Boys Adrift: The Six Factors Driving the Growing Epidemic of Unmotivated Boys and Underachieving ...

Read more
News

A gut health scientist who follows the Mediterranean diet shared his go-to, fiber-packed breakfast, lunch, and dinner

August 31, 2026
News

Hegseth’s purges are endangering national security

August 31, 2026
News

Trump is spending billions to reverse American progress

August 31, 2026
News

Tim Cook was the real genius at Apple

August 31, 2026
I’m an oncologist. Every man should know this about prostate cancer.

I’m an oncologist. Every man should know this about prostate cancer.

August 31, 2026
Why a 1963 bank case should not decide the Paramount/Warner deal

Why a 1963 bank case should not decide the Paramount/Warner deal

August 31, 2026
Survivors of Cyprus Ferry Sinking Describe a Harrowing Escape

Survivors of Cyprus Ferry Sinking Describe a Harrowing Escape

August 31, 2026

DNYUZ © 2026

No Result
View All Result

DNYUZ © 2026