Two conference talks (slides)

Vulnerabilities in Full-Disk Encryption Systems (PDF)

  • Plaintext disclosure (re)discovered in BestCrypt Volume Encryption (NotCVE-2026-0004, not fixed).
  • Multiple BitLocker bypasses (CVE-2024-43513 dubbed “bitlockpick”, CVE-2025-21202 dubbed “bitlockpick 2”, CVE-2026-20928 dubbed “cold boot attack without cold and boot”, CVE-2025-21210 dubbed “CrashXTS”, CVE-2025-21214 – a bug from the 90’s).
  • CVE-2025-21215 – turning the Windows boot loader into the keylogger to capture the BitLocker’s PIN.
  • CVE-2025-4382 in GRUB.
  • One security vendor distributing a .reg file that disables the encryption of hiberfil.sys when using third-party software (like VeraCrypt).
  • Our future: wide-block ciphers & modes, authenticated encryption (operating systems are not ready here!)

I’ll hack you via a SYN packet (PDF)

  • CVE-2026-10817 in the TCP stack of NetScaler ADC and Gateway.
  • Yes, attackers can leak decrypted data via a truncated TCP timestamp!

Leave a comment