ATM flaws have exposed critical weaknesses in the software supply chain, particularly concerning widely used security software like CryptoPro Secure Disk. Security researcher Matt Burch discovered nine vulnerabilities, patched in late 2026, which could have allowed full access to encrypted devices, according to WIRED.
These findings highlight a broader challenge beyond just ATMs. Software components frequently integrate into numerous industries, making any vulnerabilities a systemic risk. The difficulty lies in the complex process of patching these issues across various systems and customer implementations.
What vulnerabilities were found in ATM security software?
Nine vulnerabilities were discovered in CryptoPro Secure Disk, a pre-boot authentication and disk encryption software. These flaws could have enabled attackers to bypass integrity checks and gain complete access to encrypted devices. The software, developed by German firm CryptWare, is used in some ATMs and other embedded systems.Burch presented these findings at the Black Hat and Defcon security conferences in August 2026. CryptWare addressed these bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December 2026. Burch confirmed the effectiveness of these patches.
One prominent user of CryptoPro is Diebold Nixdorf, which incorporates the software into its Vynamic Security Suite. Diebold Nixdorf spokesperson Michael Jacobsen stated that only two of the nine vulnerabilities were relevant to their Vynamic Security Hard Disk Encryption. Fixes for these were issued in December 2026.
How do AI tools impact vulnerability discovery and patching?
AI systems significantly enhance the ability to evaluate software and find vulnerabilities, even for researchers lacking deep specific expertise. This development makes the traditional 'security through obscurity' model ineffective. The ease with which AI can uncover flaws increases the urgency for transparency and timely patch adoption across all industries.The challenge of the software supply chain involves multiple steps: a developer releases a patch, implementers create tailored fixes, and customers must install updates. This process is particularly difficult for systems in the field or those that cannot easily be taken offline for maintenance. The wide implementation of software across embedded devices, ATMs, and enterprise security complicates these efforts.
Jacobsen, the Diebold Nixdorf spokesperson, emphasized their process of assessing impact, identifying affected products, and developing necessary updates. They then notify customers and provide updates through standard distribution channels. For deployed ATMs, updates are coordinated individually with customers based on operational models and service agreements.
Software Supply Chain Stage | Key Challenge | Impact of AI |
|---|---|---|
Vulnerability Discovery | Requires specialized expertise, time-consuming | Accelerates detection, lowers expertise barrier |
Patch Development | Ensuring compatibility and completeness | Can assist in code analysis for faster fixes |
Deployment & Installation | Coordination with customers, system downtime | Identifies dependencies, optimizes deployment strategies |








