@lxo the vote disclosure you mention was caused by a poorly chosen RNG seed, that allowed the attacker to duplicate the shuffling sequence of votes for that individual machine.
That specific flaw was, AFAIK, fixed.
As to independently verify and attack the machines, the parties and many other organizations and independent testers have access to the code and can request voting machines to be tested in realistic environments.