Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology
UNDERREPORTED

Researchers expose nine flaws in ATM encryption software and warn of broader supply-chain risks

Security researcher Matt Burch disclosed nine vulnerabilities in CryptoPro Secure Disk, a German encryption tool used in ATMs and other embedded systems, prompting patches from CryptWare and limited fixes from Diebold Nixdorf.

For half a decade, Matt Burch has focused on ATM security, and his latest work reveals nine exploitable bugs in CryptoPro Secure Disk, a disk-encryption and pre-boot authentication product from the German firm CryptWare. Presented at Black Hat and Defcon in Las Vegas, the flaws could bypass CryptoPro’s integrity checks and grant full access to encrypted hardware. CryptWare responded with two patch releases—version 7.7.2 in early November and 7.7.3 in early December—and Burch verified that the updates close the gaps.

Diebold Nixdorf, which incorporates CryptoPro in its Vynamic Security Suite, acknowledged that only two of the vulnerabilities relate to its ATM encryption and that the company issued its own fixes in December, noting the bugs alone would not let attackers compromise a Diebold Nixdorf ATM. The case underscores the layered challenges of software-supply-chain security: developers must issue patches, integrators must adapt them, and end users must apply them, a process often hampered by devices that remain in continuous operation. Burch also warned that AI tools now make it easier to discover such weaknesses, reducing the effectiveness of “security through obscurity.”

Why it matters

Flaws in widely used encryption software can expose critical infrastructure, and slow patch adoption magnifies the risk.

In this story

ATM securitysoftware supply chainCryptoPro vulnerabilitiespatch deploymentAI and vulnerability discoveryembedded devicespre-boot authentication
Get the beta ↗