Atredis is a 100% worker-owned team of world-class security researchers and consultants. We do risk-centric, research-driven security testing and consulting.
Atredian Matt Burch (@emptynebuli) will be presenting his ATM supply chain research and demonstrating new exploitation tooling at @GrrCon!
π Friday, Sept 25 @ Noon
π Abstract: buff.ly/GvZm49g
π¨ Our research just hit @WIRED!
Atredian Matt Burch's (@emptynebuli) latest research highlights gaps in the ATM software supply chain, allowing for malicious system access via the controls designed to protect the platform! Read the full story: buff.ly/GKJwanu
This September Atredian Matt Burch (@emptynebuli) will be presenting "Compounding Interest: Exploiting the ATM Supply Chain" at @GrrCon in GrandRapids MI. Come learn about the ATM supply chain attack surface.
π Friday, Sept 25 @ Noon
π Abstract: buff.ly/GvZm49g
Planning your @defcon week? Be sure to add CAPTURE_THE_COIN CTF to your list and catch Matt Burch's encore presentation of "Compounding Interest: Exploiting the ATM Supply Chain." Watch the talk, then put those TTPs to the test in the CryptoPro CTF.
buff.ly/yfRaHli
In 1hr at @BlackHatEvents, join Matt Burch (@emptynebuli) as he dives into the ATM supply chain. In his briefing, Matt will be disclosing 9 CVEs and officially releasing his tooling, ragavan.
π 2:35 PM in South Seas C&D, Level 3
#BlackHat#BHUSAbuff.ly/8Hnubnk
Atredians are in the air headed to Vegas for #BlackHat and #DEFCON!
We always look forward to learning, sharing, and connecting with the community.
If you see one of our shirts in the hall be sure to stop us and say hi!
9 CVEs, 1 new tool, and a deep dive into the ATM supply chain.
@defcon is exactly 1 week out! Catch Matt Burch (@emptynebuli) present Compounding Interest: Exploiting the ATM Supply Chain.
ποΈ AUG 8, 12:30PM
π Main Track 4
#DEFCON#DEFCON34#Hackingbuff.ly/fDeMQhh
If you are heading to @DefCon this summer, don't miss Atredian Matt Burch (@emptynebuli) and his continued CryptoPro research in Compounding Interest: Exploiting the ATM Supply Chain. He will be on the main stage Track 4, Saturday Aug 8 at 12:30.
buff.ly/fDeMQhh
Atredian Matt (@emptynebuli) spoke with @DarkReading about his upcoming @BlackHatEvents talk "The Cost of Obscurity: Exploiting the ATM Supply Chain" ποΈ π΅
Bottom line: Disk encryption doesn't help if the keys are stored right next to the lock. buff.ly/E1BRVhk
"Bad News for the Average Pentester" ... But who wants to be average?
Here's some thoughts from Shawn on why Human-Powered Pentesting is here to stay.
atredis.com/blog/2026/5/15/bβ¦
We decided to revisit an old research problem with some new LLM powered tooling. Check out our latest blog post to see how we approached this research, and the new Java deserialization gadget chains it discovered in just two days! buff.ly/CeAQZ2B
On a recent engagement, we exploited a previously disclosed privilege escalation bug in Tenable's Nessus Agent. No public PoC was available, so we made one; check it out here buff.ly/IMMQWEo
Atredis identified a vulnerability in the way Rapid7's Nexpose was generating passwords to protect its Java KeyStore which is used to encrypt saved credentials. This vulnerability was reported to Rapid7 and a patch is being rolled out today! Details here: buff.ly/U7qaplX