Security News

Cybersecurity news aggregator

HIGH Vulnerabilities Dark Reading

Fresh ATM Crypto Software Bugs: Jackpot or Bust?

A researcher has discovered nine vulnerabilities in CryptWare CryptoPro Secure Disk, a full-disk encryption solution used by ATMs and corporations, which could potentially allow physical attackers to compromise the ATM's head unit and manipulate the software to dispense cash. The article does not provide CVSS scores, specific affected or fixed version numbers, or any recommended workarounds.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS CYBER RISK ENDPOINT SECURITY CYBERATTACKS & DATA BREACHES NEWS Fresh ATM Crypto Software Bugs: Jackpot or Bust? Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper. Nate Nelson,Contributing Writer July 10, 2026 5 Min Read SOURCE: ATM29 VIA GETTY IMAGES A researcher has discovered nine vulnerabilities in an ATM and corporate security program. The researcher and major ATM manufacturer Diebold Nixdorf disagree, though, about whether it could allow attackers to steal cash or not. At Black Hat USA 2026, Matt Burch, principal security researcher for Atredis Partners, will present nine new vulnerabilities he discovered in CryptWare CryptoPro Secure Disk. CryptoPro, for short, is a full‑disk encryption (FDE) and pre‑boot authentication solution for Windows that, strangely, is marketed to both corporations generally and ATM manufacturers specifically. LOADING... There isn't any controversy over Burch's findings themselves. Rather, the question is whether they're meaningful. Burch describes CryptoPro as "foundational" to a security suite used by the world's largest ATM manufacturer, Diebold. Diebold tells Dark Reading that it isn't. In other words, Burch has either uncovered a way to steal hundreds of thousands of dollars from ATMs or he found issues with a reasonably popular enterprise security tool. Related:Microsoft Reins in RoguePlanet Zero-Day Threat How ATMs Are Secured (or Not) Against Attackers ATMs are heavily padded on the bottom, with less protection up top. The bottom portion is where the money is, of course. The top portion is where the computing happens. The problem, from a cybersecurity perspective, Burch explains, is that "[Manufacturers] don't necessarily consider the top portion of the ATM where all the PC components are a significant security risk. It's constructed with lower-grade steel," or even plastic. Breaking into the vault half of the machine is a seismic task for any thief, but this cheaper head unit is more manageable. "The locking mechanism is essentially operated by a cable. You have the lock solenoid and then there's a cable attached to that, which pulls levers on either side of the case of the ATM, which opens up the front portion. Access to those cables can be done through physical damage, or you could insert tools," Burch explains. On the inside, he continues, "ATMs have a stack of software that gets placed on Windows [including] a bunch of banking configurations so the ATM can dispense funds. It's a rather lengthy process to set up and manipulate, but under the hood, it actually all relies on a single dynamic link library (DLL). And the DLL is referenced as extension for financial services, XFS." XFS is what connects users to their banks, and enables the dispensation of funds. Instead of casing a joint, then, thieves can more easily steal money by de-casing an ATM, and wiring in malware to reach XFS. The most well-known ATM malware is called "Ploutus." Since the first ATM "jackpotting" attacks were spotted in the US in 2017, they've only grown more and more common. Of the 2,000 or so that have been reported to the FBI since 2020, more than 700 occurred in 2025 alone, representing more than $20 million stolen. Related:CitrixBleed-ing Again? NetScaler Vulnerability Under Attack Where the New Security Bugs Come In All ATM manufacturers have some kind of proprietary security software to defend against jackpotting. For example, Diebold offers an all-in-one Vynamic Security Suite (VSS). Among other features, VSS offers hard disk encryption (HDE). This HDE component integrates a third-party program called CryptoPro Secure Disk, in which Burch found his vulnerabilities. A couple of those weaknesses concerned how CryptoPro decrypted the hard drive during pre-boot. If a fail state was introduced, and decryption failed, it would default to mounting volumes in plaintext. And thanks to a superficial check for whether the disk was using LUKS encryption, a hacker could potentially make a disk look encrypted and therefore trick the system into mounting, again, in plaintext. Besides that, Burch also found that CryptoPro's own key material and configuration values were stored on the disk itself, rather than somewhere more secure. In combination with the plaintext issue, it allowed him full view of the program's most guarded secrets. He also found that CryptoPro's Secure Boot setup allowed an attacker to run their own, arbitrary Linux environment on an ATM, instead of the vendor's environment. Related:Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. Altogether, these issues allowed the researcher to get his own code running on the ATM during pre-boot, recover the keys he needed to decrypt its Windows environment, and steal cash using a standard jackpotting flow. Does This Actually Impact ATMs? Dark Reading contacted CryptoPro vendors CryptWare and CPSD, as well as Diebold Nixdorf, for comment on this story. The encrypters didn't respond, but the ATM manufacturer took the opportunity to dispute the researcher's claims. Mike Jacobsen, senior director of corporate communications for Diebold, tells Dark Reading that his company doesn't actually use BitLocker, let alone CryptoPro Secure Disk for BitLocker. "Therefore, the findings are not directly applicable to us," he argues. At the same time, Jacobsen acknowledges that Diebold ATMs "use some components of CryptoPro in our Vynamic Security HDE." When asked to clarify how exactly Diebold implements CryptoPro, Jacobsen declined to comment further. Burch speculates that "they may be relying on one of CryptoPro's alternative cryptographic mechanisms instead." CryptoPro Secure Disk is listed in both the 2018 and 2024 End User License Agreements (EULAs) for Diebold VSS. In response to Burch's bug reports, Diebold worked with CryptoPro's developers to assess its impact on its ATMs. The consensus, Jacobsen says, was that "the findings pose little to no additional risk to our ATMs in a real-world environment," though he concedes that an undisclosed two among Burch's nine vulnerabilities "are theoretically applicable to our HDE under certain conditions." Diebold appears to have quietly addressed those issues in a December 2025 update. Regardless of whether two or nine of the vulnerabilities impacted Diebold ATMs, CryptoPro is also reasonably widely used in organizations that operate Windows fleets. On its landing page, the vendor claims to have supplied more than 500,000 licenses across five continents, and 20 industries. For those organizations, too, "It's important to ensure that whenever you're using cryptography or encryption, the secrets are also secured and not easily generated or recovered," Burch says. "If you give someone a lockbox and then the key is right next to the box, it defeats the purpose of having the box locked to begin with." Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars You May Also Like VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan, Contributing Writer NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 VULNERABILITIES & THREATS 350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE by Nate Nelson, Contributing Writer JUL 11, 2025 Editor's Ch

Share this article