Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities Wired Security

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

  • What: A researcher discovered nine vulnerabilities in ATM encryption and authentication software.
  • Impact: Potential risks extend beyond ATMs to other critical systems.
Read Full Article →

Lily Hay Newman Security Aug 31, 2026 6:00 AM ATM Flaws Reveal Key Weaknesses in the Software Supply Chain A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine. Photo-Illustration: Jobanny Cabrera; Getty Images Save this story Save this story For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash . As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has started working to raise the alarm, not just about overlooked ATM flaws, but about how that same software used in other industries can introduce weaknesses in an array of critical systems. At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices. Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite. But CryptoPro is also sold as a security solution for other embedded-device makers, as well as big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries. “ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that,” Burch says. “From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way and then there’s limited technical insight—bugs can get overlooked or they don’t get addressed.” CryptWare managing director Uwe Saame tells WIRED that the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. Burch says the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities he found. While CryptoPro does not seem to publicly release update notes, Burch says he believes that the company distributed information about the patches to its customers. Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED in a statement that only two of the nine vulnerabilities are relevant to Diebold Nixdorf's Vynamic Security Hard Disk Encryption, the system where the ATM maker uses CryptoPro software. Jacobsen says that Diebold Nixdorf issued fixes related to those two bugs in December, but that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM. In ATMs, embedded devices, and enterprise security more broadly, the challenge of the software supply chain comes from all of the steps to actually apply fixes in the world. As in this case, a developer has to release a patch, then companies that implement the product in their own software need to develop a tailored fix, and then customers need to actually hear about and install that patch—which can be difficult for systems that are running in the field or can't easily be paused and updated. Speaking generally about this challenge, Jacobsen, the Diebold Nixdorf spokesperson, says that “when a security issue is identified, Diebold Nixdorf assesses the impact, identifies affected products and configurations, and develops any needed updates through our product security and engineering processes. We then notify impacted customers and provide updates through standard software distribution channels, including the Global Security Portal where applicable. For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes.” Security researchers have warned for decades about the danger of relying on “security through obscurity” by trying to hide software from view or keep it locked away. And, as a result of this work, internet-of-things manufacturers and those in critical industries like the financial sector and medical device manufacturing have made some progress on transparency and promoting patch adoption. But Burch points out that as AI systems make it easier to evaluate software and find vulnerabilities —even for researchers or attackers who don't have granular expertise in a given area—it is more pressing than ever to shed light on niche security products. “AI really blows away the obscurity model,” Burch says. “You don’t need to fully understand how something works anymore to move forward and potentially have a big impact.” Comments Back to top Join the discussion Comments Back to top You Might Also Like In your inbox: Maxwell Zeff's dispatch on the business of AI Why normal people aren’t using AI agents Big Story: How data centers broke American politics Hackers stalked me by hijacking a cheap pink plastic watch Special edition: The WIRED guide to expanding your mind Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate, and was the staff writer for Future Tense, a publication and partnership between Slate, the New America Foundation, and Arizona State University. Her work ... Read More Senior Writer Topics security cybersecurity vulnerabilities hacking software black hat DefCon Read More A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device. Lily Hay Newman This Coin-Sized Device Can Hack a Boeing 737 Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan. Andy Greenberg Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets. Matt Burgess OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose. Lily Hay Newman Hackers Stalked Me by Hijacking a Smartwatch for Kids Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets. Andy Greenberg OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase. Matt Burgess Election Officials Are Preparing for Prediction Markets to Sow Chaos in the Midterms From threats to the safety of poll workers to voters who can’t distinguish between odds and results, prediction markets are already scrambling the political process. David Gilbert The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise. Lily Hay Newman A New Trick Reveals AI Models’ Inner Thoughts Researchers devised a way to extract “reasoning traces” from Claude, GPT, and Gemini. What they found, they say, indicates that some Chinese AI may be trained on leading US models. Will Knight The Password Managers You Should Use Instead of Your Browser Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers. Scott Gilbertson The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here Z.ai’s latest AI model release could help companies secure their systems—or find its way into the hands of hackers. Will Knight One of China’s Most Powerful AI Models Has Also Escaped Containment Security researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given. Will Knight

Share this article