Ethical Hacking News
A recent discovery by security researcher Matt Burch highlights the vulnerabilities in CryptoPro Secure Disk, a software solution used in ATMs and other industries. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices. This discovery underscores the need for greater transparency and patch adoption in the software supply chain, as well as the challenge of addressing software vulnerabilities in a global industry.
Security researcher Matt Burch discovered vulnerabilities in CryptoPro Secure Disk, a software solution used in ATMs, which could have exposed encrypted devices. The flaws were patched by CryptoPro in two phases, with the company being prompt and collaborative throughout the disclosure process. Diebold Nixdorf's Vynamic Security Suite was also affected, but only two of the nine vulnerabilities were relevant to the system. The discovery highlights the challenge of the software supply chain and the need for greater transparency and patch adoption. AI systems are making it easier to find vulnerabilities, and security through obscurity is a concern, making collaboration in addressing software vulnerabilities essential.
Security researcher Matt Burch has spent the past five years immersing himself in the high-stakes world of ATM security, a domain where small software flaws can sometimes expose cold, hard cash. Burch's journey into the world of ATM security led him to discover vulnerabilities in key digital security systems, including disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices.
CryptoPro Secure Disk is a software solution marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite. However, the software is also sold to other embedded-device makers and big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries. Burch's findings highlight the need for greater transparency and patch adoption in the software supply chain.
CryptWare managing director Uwe Saame tells WIRED that the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. Burch says the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities he found. While CryptoPro does not seem to publicly release update notes, Burch says he believes that the company distributed information about the patches to its customers.
Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED in a statement that only two of the nine vulnerabilities are relevant to Diebold Nixdorf's Vynamic Security Hard Disk Encryption, the system where the ATM maker uses CryptoPro software. Jacobsen says that Diebold Nixdorf issued fixes related to those two bugs in December, but that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.
Burch's discovery of the vulnerabilities highlights the challenge of the software supply chain, which involves multiple steps to apply fixes. A developer must release a patch, then companies that implement the product in their own software need to develop a tailored fix, and then customers need to actually hear about and install that patch. This can be difficult for systems that are running in the field or can't easily be paused and updated.
The issue of security through obscurity is also a concern, as security researchers have warned for decades about the danger of relying on this approach. The work of Burch and other security researchers has led to progress in transparency and promoting patch adoption in the software supply chain. However, the increasing ease of evaluating software and finding vulnerabilities, thanks to the advent of AI systems, highlights the need for greater transparency and collaboration in addressing software vulnerabilities.
According to Burch, "AI really blows away the obscurity model." He notes that without the need to fully understand how something works, researchers or attackers can move forward and potentially have a big impact. The discovery of the vulnerabilities in CryptoPro Secure Disk and the subsequent patches highlight the importance of shedding light on niche security products and the need for greater collaboration in addressing software vulnerabilities.
In conclusion, the discovery of the vulnerabilities in CryptoPro Secure Disk highlights the need for greater transparency and patch adoption in the software supply chain. The issue of security through obscurity and the challenge of the software supply chain are also pressing concerns. As AI systems become more prevalent, it is essential to shed light on niche security products and promote greater collaboration in addressing software vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Vulnerabilities-A-Threat-to-the-Global-Software-Supply-Chain-ehn.shtml
https://www.wired.com/story/atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain/
Published: Mon Aug 31 05:59:48 2026 by llama3.2 3B Q4_K_M