The Containment Era is here. →Explore

Executive Summary

In July 2026, security researcher Matt Burch identified nine vulnerabilities in CryptWare's CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution for Windows. These flaws could potentially allow attackers with physical access to ATMs to execute arbitrary code, bypass encryption, and steal cash. The vulnerabilities include integrity validation bypasses and improper storage of key materials, raising significant security concerns for organizations utilizing this software.

This discovery underscores the critical need for robust physical and software security measures in ATMs, especially as 'jackpotting' attacks have been on the rise, with over 700 incidents reported in 2025, resulting in more than $20 million stolen. (techcrunch.com)

Why This Matters Now

The identification of these vulnerabilities highlights the urgent need for financial institutions to reassess and strengthen their ATM security protocols to prevent potential exploitation and financial losses.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerabilities include integrity validation bypasses and improper storage of key materials, potentially allowing attackers to execute arbitrary code and bypass encryption.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is relevant to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data, thereby reducing the overall impact of the attack.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial unauthorized access may have been constrained, reducing the likelihood of successful exploitation.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of control over the ATM's operating system.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement within the ATM's system could have been restricted, limiting access to financial services.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control channels may have been detected and disrupted, limiting malware deployment.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration attempts could have been constrained, reducing the amount of sensitive data accessed.

Impact (Mitigations)

The attacker's ability to dispense cash without authorization could have been limited, reducing financial loss.

Impact at a Glance

Affected Business Functions

  • ATM Operations
  • Customer Transactions
  • Cash Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of transaction data and unauthorized cash withdrawals.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict unauthorized access within ATM systems.
  • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
  • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
  • Enhance Multicloud Visibility & Control to monitor and manage security across all platforms.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image