Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Bring On the MAGA Revolt

17 July 2025

Nothing Phone 3 Said to Have a Sturdy, Repairable Build; Teardown Video Suggests

17 July 2025

iPhone 17 Pro, iPhone 17 Pro Max to Feature Scratch-Resistant, Anti-Reflective Display Coating: Report

17 July 2025
Facebook X (Twitter) Instagram
Just In
  • Bring On the MAGA Revolt
  • Nothing Phone 3 Said to Have a Sturdy, Repairable Build; Teardown Video Suggests
  • iPhone 17 Pro, iPhone 17 Pro Max to Feature Scratch-Resistant, Anti-Reflective Display Coating: Report
  • Asus NUC 15 Pro Mini PC Launched in India With Intel Core Ultra Processor Series 2: Price, Specifications
  • Google Expands Same Day Repair Service for Pixel Phones, Watch and Buds to 21 Cities in India
  • Samsung Galaxy F36 5G: Launch Date, Expected Price in India, Specifications, Features and More
  • Google Pixel 10 Series Launch Event Reportedly Set for August 20: What to Expect
  • iPhone Models With China-Made Displays Reportedly Face Ban in the US; Apple Says ‘No Effect’ on Products
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » ATM Software Flaws Left Piles of Cash for Anyone Who Knew to Look
News

ATM Software Flaws Left Piles of Cash for Anyone Who Knew to Look

News RoomBy News Room9 August 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

There is a grand tradition at the annual Defcon security conference in Las Vegas of hacking ATMs. Unlocking them with safecracking techniques, rigging them to steal users’ personal data and PINs, crafting and refining ATM malware and, of course, hacking them to spit out all their cash. Many of these projects targeted what are known as retail ATMs, freestanding devices like those you’d find at a gas station or a bar. But on Friday, independent researcher Matt Burch is presenting findings related to the “financial” or “enterprise” ATMs used in banks and other large institutions.

Burch is demonstrating six vulnerabilities in ATM-maker Diebold Nixdorf’s widely deployed security solution, known as Vynamic Security Suite (VSS). The vulnerabilities, which the company says have all been patched, could be exploited by attackers to bypass an unpatched ATM’s hard drive encryption and take full control of the machine. And while there are fixes available for the bugs, Burch warns that, in practice, the patches may not be widely deployed, potentially leaving some ATMs and cash-out systems exposed.

“Vynamic Security Suite does a number of things—it has endpoint protection, USB filtering, delegated access, and much more,” Burch tells WIRED. “But the specific attack surface that I’m taking advantage of is the hard drive encryption module. And there are six vulnerabilities, because I would identify a path and files to exploit, and then I would report it to Diebold, they would patch that issue, and then I would find another way to achieve the same outcome. They’re relatively simplistic attacks.”

The vulnerabilities Burch found are all in VSS’s functionality to turn on disk encryption for ATM hard drives. Burch says that most ATM manufacturers rely on Microsoft’s BitLlocker Windows encryption for this purpose, but Diebold Nixdorf’s VSS uses a third-party integration to run an integrity check. The system is set up in a dual-boot configuration that has both Linux and Windows partitions. Before the operating system boots, the Linux partition runs a signature integrity check to validate that the ATM hasn’t been compromised, and then boots it into Windows for normal operation.

“The problem is, in order to do all of that, they decrypt the system, which opens up the opportunity,” Burch says. “The core deficiency that I’m exploiting is that the Linux partition was not encrypted.”

Burch found that he could manipulate the location of critical system validation files to redirect code execution; in other words, grant himself control of the ATM.

Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED that Burch first disclosed the findings to them in 2022 and that the company has been in touch with Burch about his Defcon talk. The company says that the vulnerabilities Burch is presenting were all addressed with patches in 2022. Burch notes, though, that as he went back to the company with new versions of the vulnerabilities over the past couple of years, his understanding is that the company continued to address some of the findings with patches in 2023. And Burch adds that he believes Diebold Nixdorf addressed the vulnerabilities on a more fundamental level in April with VSS version 4.4 that encrypts the Linux partition.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMotorola Edge 50 Neo Appears on TENAA; Suggests Design, Key Specifications
Next Article Best router deals: Save on mesh networks and Wi-Fi 6 routers

Related Articles

News

Bring On the MAGA Revolt

17 July 2025
News

‘Wyoming King’ and More Mattress Sizes You Probably Didn’t Know Existed

17 July 2025
News

Now Is a Very Good Time to Buy a Used EV. Here’s Why

17 July 2025
News

Review: Bedsure Cooling Sheets

17 July 2025
News

Trump and the Energy Industry Are Eager to Power AI With Fossil Fuels

16 July 2025
News

Dyneema’s New Fiber Composite Is Lighter, Stronger, and More Durable Than Ever

16 July 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024101 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Phones

Samsung Galaxy F36 5G: Launch Date, Expected Price in India, Specifications, Features and More

News Room17 July 2025
Phones

Google Pixel 10 Series Launch Event Reportedly Set for August 20: What to Expect

News Room17 July 2025
Phones

iPhone Models With China-Made Displays Reportedly Face Ban in the US; Apple Says ‘No Effect’ on Products

News Room17 July 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025124 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024101 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Asus NUC 15 Pro Mini PC Launched in India With Intel Core Ultra Processor Series 2: Price, Specifications

17 July 2025

Google Expands Same Day Repair Service for Pixel Phones, Watch and Buds to 21 Cities in India

17 July 2025

Samsung Galaxy F36 5G: Launch Date, Expected Price in India, Specifications, Features and More

17 July 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.