Product1 distinct publisher3 min readPublished
CryptWare shipped fixes in two releases without publishing update notes, and the ATM maker that embeds the software says only two bugs touched its product. Who else runs it is the harder question, and the answer is not written down anywhere.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
For most fleets, CryptoPro Secure Disk is not in the asset register at all, because the pre-boot layer arrived inside a product a device maker built and integrated, which is how the software ended up in some ATMs by way of Diebold Nixdorf's Vynamic Security Suite [4].
Teams tend to assume the asset register covers operating systems and the applications that have vendor portals. In practice it covers the line items procurement signed. Disk encryption and pre-boot authentication that a manufacturer embedded is a dependency rather than a purchase, so it sits in nobody's patch queue by default.
The propagation path has three hops before a fix reaches a running machine. The developer releases a patch, the company that implements the product builds a tailored fix, and then the customer has to hear about it and install it, which is hard for equipment in the field that cannot easily be paused [11]. CryptWare's managing director, Uwe Saame, says the nine bugs went out in two phases, 7.7.2 in early November and 7.7.3 in early December [6]. CryptoPro does not appear to publish update notes publicly, and Burch believes the company told its own customers directly [8]. If you are not a customer of record, there is nothing to read.
Diebold Nixdorf's spokesperson says two of the nine are relevant to its Vynamic Security Hard Disk Encryption, that fixes went out in December, and that neither bug could have compromised one of its ATMs on its own [9]. Subtract and seven are, by that account, somebody else's problem to scope [14]. The Wired account carries scoping from exactly one integrator, and none from the other embedded-device makers or the large Windows shops also named as buyers [5][15]. It also dates the Black Hat and Defcon talks as "this month" while dating the patches to early November and December without years, so a reader cannot compute how long the fixed bugs sat before disclosure [16].
Burch's own argument is that the obscurity these niche products relied on is thinning, because AI tooling lets people assess unfamiliar software without deep domain expertise [13]. The practical response is to put the pre-boot layer on the same register you already keep for the OS. The tradeoff is that you will be tracking versions you cannot patch yourself, and your only lever is the integrator's change-management calendar, which is where Diebold says deployed ATM updates get coordinated per customer [12].
Two questions sort the work. Can you name the pre-boot and full-disk-encryption component and its version on a given fleet, and can you update it without touching the hardware.
- Named and remotely updatable: ordinary patch work. - Named, physical touch required: a scheduling and truck-roll problem, budgeted rather than debated. - Unnamed but remotely updatable: one call to the vendor of record fixes the gap permanently. - Unnamed and physical: you are trusting a notification you may never see, for a component you cannot look up.
The cheap version of this is a line in the next renewal asking the vendor to name the third-party crypto components in its product and say where their fixes get published. Researchers have spent decades arguing against security through obscurity, and finance and medical device makers have made some progress on transparency and patch adoption [17]. Progress in the vendor's disclosure practice is not the same as progress in your register.
Ranked by verification strength, evidence, and original report placement.
Diebold Nixdorf spokesperson Michael Jacobsen says only two of the nine vulnerabilities are relevant to its Vynamic Security Hard Disk Encryption, that fixes for those two were issued in December, and that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.
Security researcher Matt Burch has spent the past five years researching ATM security and finding vulnerabilities in the digital security systems powering ATMs.
At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities, since fixed, in disk encryption and pre-boot authentication software called CryptoPro Secure Disk.
The nine flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices.
CryptoPro is made by the German software firm CryptWare, is marketed to ATM makers, and is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite.
CryptoPro is also sold as a security solution for other embedded-device makers and for large organizations using Microsoft Windows.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The dependency gate moves upstream: why post-commit SCA misses hallucinated packages1 distinct publisher
build
AWS gives software supply chain its own Security Hub category, with two vendors in it1 distinct publisher
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named sources, no paper trail
Three of the four people who could settle this are quoted by name: the researcher, CryptWare's managing director, and Diebold Nixdorf's spokesperson. That is unusually good for a component-level bug story. What is absent is anything a reader could check independently — no CVE identifiers, no advisory, no release notes, no conference abstract. Every technical assertion terminates in someone's statement to WIRED.
Fixed upstream, unmeasured downstream
Two vendor releases and one integrator fix are documented by version and month, which is real movement. Beyond that the trail goes cold: not one machine, bank, or embedded-device maker is described as having installed anything, and Diebold Nixdorf's own words concede that fielded ATMs get updated on each customer's schedule. The software is sold into Windows fleets and other embedded products, and this reporting names no buyer in either category.
Reach claimed, reach not shown
The reporting is careful where it counts — the flaws are described as fixed, the researcher confirms it, and nobody claims exploitation in the wild. The stretch is in the framing. The supply-chain thesis and the line about impact beyond ATMs both need a broad installed base to bite, and that base appears only as a sentence about who the product is marketed to. The mildest inflation, not the loudest.
Two parties, two counts
Note who supplies which number. The vendor supplies the version history that shows it patched quickly; the integrator supplies the count that shrinks nine bugs to two and adds that neither worked alone; the researcher, presenting at Black Hat and Defcon, supplies the framing that the findings reach beyond ATMs. None of these is dishonest and all three are self-interested, and because CryptoPro publishes no update notes, no outside document arbitrates between them.
Solid on the record, thin off it
We are confident about what each party said and much less confident about the world those statements describe. One publisher, no second account, and a timeline that will not resolve: the talks are dated only as "this month" and the fixes to early November and early December, so how long users ran unpatched code — or whether disclosure followed the fixes by weeks or by most of a year — is simply not determinable from what is in front of us.