For five years, security researcher Matt Burch has delved into the world of ATM security, unearthing vulnerabilities that could expose cash to cyber threats. His recent findings at the Black Hat and Defcon conferences underscore the broader risks of software supply chains, where critical systems can be compromised by overlooked bugs.
The CryptoPro Secure Disk software, used in ATMs and other industries, has nine known vulnerabilities. Although patched, the process of applying these fixes across various systems highlights the challenges of ensuring security updates are effective and timely.
Diebold Nixdorf, which uses CryptoPro in its Vynamic Security Suite, found only two vulnerabilities relevant to their systems. They addressed these promptly, but the broader issue remains: how can we ensure all systems are patched to mitigate risks?
As artificial intelligence makes it easier to identify vulnerabilities, the importance of transparency in security products cannot be overstated. Burch’s work suggests that hidden software no longer guarantees safety, and the digital age demands clearer, more robust security measures.







