[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhHw_ScehANQDowWxDy4zXsNdla3ltKdnU7UtfK2YZ58":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"db519d97-4359-42eb-9618-0be6758e36e2","atm-encryption-software-flaws-expose-supply-chain-risk","511e59d8-4062-49f1-ac07-1884cfa0e922","ATM Encryption Software Flaws Expose Supply Chain Risk","Nine vulnerabilities in CryptoPro Secure Disk — software embedded in ATMs and other critical systems — allowed attackers to bypass integrity checks and gain full control of encrypted devices, exposing a fundamental weakness in third-party software dependencies. The root issue is a classic supply chain problem: a single vendor's flawed component can silently introduce critical risk across countless downstream customers who may not even be aware the software is in use. While the vendor patched the flaws, the real danger lies in the propagation gap — the time between a vendor releasing a patch and every downstream operator actually applying it. This incident underscores that organizations cannot rely solely on vendors to protect them; they must actively track third-party software components and enforce timely patch adoption.","**Immediate actions:**\n- Audit all ATM and critical infrastructure systems to identify any instances of CryptoPro Secure Disk and apply the latest vendor patches immediately.\n- Conduct an emergency inventory sweep of all third-party software embedded in operational technology (OT) and critical systems.\n\n**Long-term improvements:**\n- Maintain a comprehensive Software Bill of Materials (SBOM) for all systems to enable rapid identification of affected assets when vendor vulnerabilities are disclosed.\n- Establish contractual SLAs with software vendors requiring timely vulnerability disclosure and defined patch release windows.\n- Implement a formal third-party risk management program that includes periodic security assessments of critical software dependencies.\n\n**Detection measures:**\n- Deploy file integrity monitoring (FIM) on systems running disk encryption or pre-boot authentication software to detect unauthorized changes.\n- Subscribe to vendor security advisories and threat intelligence feeds relevant to embedded and OT software components to reduce disclosure-to-patch lag time.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","NIST SP 800-161: Supply Chain Risk Management Practices","NIST CSF ID.SC-2: Suppliers and third-party partners of information systems are identified","NIST SI-2: Flaw Remediation","NIST SR-3: Supply Chain Controls and Processes","ISO\u002FIEC 27036: Information Security for Supplier Relationships","ITIL Change Management: Emergency Change Procedures","GDPR Article 32: Security of Processing (for any ATMs handling personal data)","published","2026-08-31T12:21:41.247108+00:00","2026-08-31T12:21:41.117+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fatm-flaws-reveal-key-weaknesses-in-the-software-supply-chain\u002F","atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain-4194b5","ATM Flaws Reveal Key Weaknesses in the Software Supply Chain",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]