ATM Bugs Expose Software Supply Chain Risks

Jeff Liu··3 min read·IT
ATM Bugs Expose Software Supply Chain Risks
ListenATM Bugs Expose Software Supply Chain Risks
0:00
--:--

Key Takeaways

  1. 1Matt Burch found nine vulnerabilities in CryptoPro Secure Disk, patched in late 2026.
  2. 2Nine CryptoPro Secure Disk flaws could grant full access to encrypted devices.
  3. 3Diebold Nixdorf fixed two CryptoPro vulnerabilities in its Vynamic Security Suite by December 2026.
  4. 4AI tools accelerate vulnerability discovery, rendering traditional 'security through obscurity' ineffective.

ATM flaws have exposed critical weaknesses in the software supply chain, particularly concerning widely used security software like CryptoPro Secure Disk. Security researcher Matt Burch discovered nine vulnerabilities, patched in late 2026, which could have allowed full access to encrypted devices, according to WIRED.

These findings highlight a broader challenge beyond just ATMs. Software components frequently integrate into numerous industries, making any vulnerabilities a systemic risk. The difficulty lies in the complex process of patching these issues across various systems and customer implementations.

What vulnerabilities were found in ATM security software?

Nine vulnerabilities were discovered in CryptoPro Secure Disk, a pre-boot authentication and disk encryption software. These flaws could have enabled attackers to bypass integrity checks and gain complete access to encrypted devices. The software, developed by German firm CryptWare, is used in some ATMs and other embedded systems.

Burch presented these findings at the Black Hat and Defcon security conferences in August 2026. CryptWare addressed these bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December 2026. Burch confirmed the effectiveness of these patches.

One prominent user of CryptoPro is Diebold Nixdorf, which incorporates the software into its Vynamic Security Suite. Diebold Nixdorf spokesperson Michael Jacobsen stated that only two of the nine vulnerabilities were relevant to their Vynamic Security Hard Disk Encryption. Fixes for these were issued in December 2026.

How do AI tools impact vulnerability discovery and patching?

AI systems significantly enhance the ability to evaluate software and find vulnerabilities, even for researchers lacking deep specific expertise. This development makes the traditional 'security through obscurity' model ineffective. The ease with which AI can uncover flaws increases the urgency for transparency and timely patch adoption across all industries.

The challenge of the software supply chain involves multiple steps: a developer releases a patch, implementers create tailored fixes, and customers must install updates. This process is particularly difficult for systems in the field or those that cannot easily be taken offline for maintenance. The wide implementation of software across embedded devices, ATMs, and enterprise security complicates these efforts.

Jacobsen, the Diebold Nixdorf spokesperson, emphasized their process of assessing impact, identifying affected products, and developing necessary updates. They then notify customers and provide updates through standard distribution channels. For deployed ATMs, updates are coordinated individually with customers based on operational models and service agreements.

Software Supply Chain Stage

Key Challenge

Impact of AI

Vulnerability Discovery

Requires specialized expertise, time-consuming

Accelerates detection, lowers expertise barrier

Patch Development

Ensuring compatibility and completeness

Can assist in code analysis for faster fixes

Deployment & Installation

Coordination with customers, system downtime

Identifies dependencies, optimizes deployment strategies

How to Address Software Supply Chain Risks

Learn key actions for founders, developers, organizations, and security teams to mitigate software supply chain vulnerabilities and improve security posture.

  1. 1

    Prioritize SBOMs

    Founders should prioritize creating and maintaining Software Bill of Materials (SBOMs) to effectively track all software components, enabling quicker identification of affected systems when vulnerabilities are discovered.

  2. 2

    Implement Security-by-Design

    Developers must incorporate security-by-design principles from the initial stages of development, anticipating that AI tools will eventually uncover any potential weaknesses in the code.

  3. 3

    Invest in Robust Patch Management

    Organizations should invest in robust patch management systems and processes, particularly for embedded and legacy systems that often pose challenges for updates.

  4. 4

    Leverage AI for Vulnerability Scanning

    Security teams should utilize AI-powered vulnerability scanning tools to proactively identify and address flaws within their software dependencies.

Related Articles

More insights on trending topics and technology

The Signal

What shipped in AI this week, with the sources.

One email a week.