
Researcher Matt Burch identified flaws in software used for ATMs and embedded devices, highlighting broader supply chain security challenges.
AI-generated summary
Matt Burch has spent five years researching ATM security and software vulnerabilities. CryptoPro Secure Disk is used by ATM manufacturers and other organizations to provide disk encryption and pre-boot authentication.
For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has started working to raise the alarm, not just about overlooked ATM flaws, but about how that same software used in other industries can introduce weaknesses in an array of critical systems.
At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices.
Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite. But CryptoPro is also sold as a security solution for other embedded-device makers, as well as big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries.
“ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that,” Burch says. “From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way and then there’s limited technical insight—bugs can get overlooked or they don’t get addressed.”
CryptWare managing director Uwe Saame tells WIRED that the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. Burch says the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities he found. While CryptoPro does not seem to publicly release update notes, Burch says he believes that the company distributed information about the patches to its customers.
Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED in a statement that only two of the nine vulnerabilities are relevant to Diebold Nixdorf's Vynamic Security Hard Disk Encryption, the system where the ATM maker uses CryptoPro software. Jacobsen says that Diebold Nixdorf issued fixes related to those two bugs in December, but that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.
In ATMs, embedded devices, and enterprise security more broadly, the challenge of the software supply chain comes from all of the steps to actually apply fixes in the world. As in this case, a developer has to release a patch, then companies that implement the product in their own software need to develop a tailored fix, and then customers need to actually hear about and install that patch—which can be difficult for systems that are running in the field or can't easily be paused and updated.
Speaking generally about this challenge, Jacobsen, the Diebold Nixdorf spokesperson, says that “when a security issue is identified, Diebold Nixdorf assesses the impact, identifies affected products and configurations, and develops any needed updates through our product security and engineering processes. We then notify impacted customers and provide updates through standard software distribution channels, including the Global Security Portal where applicable. For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes.”
Security researchers have warned for decades about the danger of relying on “security through obscurity” by trying to hide software from view or keep it locked away. And, as a result of this work, internet-of-things manufacturers and those in critical industries like the financial sector and medical device manufacturing have made some progress on transparency and promoting patch adoption. But Burch points out that as AI systems make it easier to evaluate software and find vulnerabilities—even for researchers or attackers who don't have granular expertise in a given area—it is more pressing than ever to shed light on niche security products.
“AI really blows away the obscurity model,” Burch says. “You don’t need to fully understand how something works anymore to move forward and potentially have a big impact.”

Google has updated its Maps application to display Lake Ontario as 'Lake America' for U.S. users, following an executive order by President Donald Trump. The update mirrors a similar 2025 change regarding the Gulf of Mexico.

Google has updated its maps in the United States to rename Lake Ontario as Lake America following an executive order by President Donald Trump, reflecting rising trade tensions between the US and Canada. The change applies only to US users, while Canadian and international users see both names or the original name. Canadian officials, including Prime Minister Mark Carney and Premier Doug Ford, have criticized the move, citing the lake's Indigenous and historical name.

Letters to the Guardian argue that AI risks require international cooperation and safeguards rather than dramatic metaphors like 'AI Hiroshima', citing historical precedents, systemic challenges, and the need for human control over AI in weapons, infrastructure, and biological synthesis.

Google Maps has updated the name of Lake Ontario to 'Lake America' for users in the United States, citing the U.S. Geographic Names Information System's formal name change following an executive order by President Donald Trump. The change has drawn criticism from commentators and Canadian officials, who note that Apple Maps still uses 'Lake Ontario' and that the move occurs amid escalating U.S.-Canada trade tensions.
Meta has agreed to a $12.1 billion settlement with 29 US state attorneys general over allegations that its platforms harm youth mental health. The agreement mandates significant feature changes and independent audits to improve child safety on Instagram and Facebook.

A new wave of screen-free wearables, including the Fitbit Air and Garmin Cirqa, is emerging to combat digital overload. By removing displays and notifications, these devices cater to users seeking to reduce technostress while still tracking health metrics.