Embedded Systems Security Researcher, Hardware Hacker & Author of Attacking and Securing U-Boot.
The definitive hands-on technical guide to uncovering, exploiting, and fixing vulnerabilities in embedded bootloaders.
U-Boot is the de facto bootloader for millions of embedded systems, IoT devices, automotive ECUs, and SATCOM terminals worldwide. This book provides direct technical methodologies to audit, exploit, and remediate corner-case vulnerabilities and misconfigurations in production deployments.
Custom native tools, entropy generators, and glitching platforms built to solve real-world reverse engineering bottlenecks.
A high-performance, native hex editor engineered for massive firmware dumps, binary analysis, and real-time pattern inspection.
Authentic Quantum Random Number Generator deriving cryptographic entropy from the fundamental radioactive alpha-decay of Radon-222.
Why silicon, firmware, and physical-layer decisions directly dictate corporate liability, recall costs, and brand continuity.
In modern enterprise threat modeling, assuming that physical access protects a system is one of the most expensive assumptions leadership can make. How brief physical contact turns into permanent fleet-wide compromise.
Most critical hardware vulnerabilities aren't born from complex cryptographic flaws—they are born from trade-offs made during tight sprint deadlines before the first PCB prototype ever hits the fab.
Why true quantum entropy depends on two interconnected pillars: Radon-222 alpha-decay chamber timing physics and mathematical Von Neumann / XOR debiasing algorithms.
Original security research, hardware glitching experiments, and satellite communications audits.
Comprehensive analysis of satellite dish antenna radiation sidelobes, physical-layer RF interception, and ground-level attack surfaces threatening enterprise VSAT deployments.
Comparing power rail crowbar circuits with high-speed analog multiplexers for precision voltage glitching against secure microcontrollers.
Deep dive into physical entropy sources, statistical bias, min-entropy characterization, and the Trevisan / 2-universal hashing extractors used in cryptographic hardware.
Technical talks, hardware exploit demonstrations, and zero-day disclosures delivered at major international cybersecurity conferences through the years.
Comprehensive exploration of practical satellite communication exploitation vectors—covering ground-level RF sidelobe interception, hardware terminal reverse engineering, and satellite uplink telemetry vulnerabilities.
Presented live teardowns and zero-day vulnerabilities (CVE-2024-0674 / CVE-2024-0675) in Lamassu Douro Bitcoin ATMs with Dani Martinez, showcasing bus tapping, tamper bypasses, and root compromise via malicious QR codes.
Keynote presentation and technical mentoring on satellite terminal vulnerabilities, ground-station RF sidelobe interception, and hardening embedded avionics against physical and wireless exploits.
Presented Glitch.IO at Black Hat Arsenal—an open-source, high-performance hardware and software framework designed for automated voltage and electromagnetic fault injection (EMFI) and rapid glitch parameter exploration on embedded targets.
Demonstrated how precision hardware power glitching subverts cryptographic signature verification during in-field UAV firmware updates, enabling persistent unsigned code execution on drone flight controllers.
In-depth exploration of low-level bootloader security flaws and U-Boot misconfigurations in embedded Linux systems, detailing practical breakout vectors from restricted boot sequences into full root execution.
Uncovered critical sensory manipulation attacks against Analog-to-Digital Converters (ADCs) deployed in industrial control systems (ICS/SCADA) and smart grid power monitoring infrastructure.
Pioneering research into PKCS#11 cryptographic middleware vulnerabilities and smart card proxying, demonstrating remote identity exploitation of the Spanish Electronic National ID (DNIe).
National conference presentation analyzing security weaknesses in cryptographic hardware middleware and presenting tools for remote token tunneling and digital signature hijacking.
Gabriel delivers conference keynotes and provides strategic technical insights. For penetration testing, hardware security audits, and professional services, engagements are conducted exclusively through IOActive.
Over 20 years uncovering zero-day vulnerabilities in satellite communications, avionics, industrial smart grids, financial kiosks, and embedded microcontrollers.
Hi, I am Gabriel González García. Throughout my career, I have completed hundreds of advanced security assessments, physical hardware teardowns, reverse engineering investigations, and firmware exploitation engagements across the globe.
My pioneering research focuses on breaking down the boundaries between theoretical hardware flaws and practical real-world exploitation—spanning SATCOM RF sidelobe interception, physical power glitching on drone flight controllers, cryptographic bus tapping on Bitcoin ATMs, and smart grid controller exploitation.
Demonstrated how sub-microsecond power glitching pulses subvert digital signature verification routines during in-field drone firmware updates, enabling persistent root compromise.
Audited physical bus interception, microswitch sensor bypasses, and software update flaws in Lamassu Bitcoin ATMs that allowed complete kiosk compromise and cash dispenser manipulation.
Reverse-engineered proprietary hardware cryptographic acceleration routines and AES-CCM wireless protocols within Nordic Semiconductor nRF SoCs, revealing implementation weaknesses in secure RF communications.
CVE-2025-11778 through CVE-2025-11789: Discovered multiple critical remote execution and authentication bypass vulnerabilities in SGE-PLC1000 & SGE-PLC50 industrial power grid concentrators.
CVE-2025-41377 to CVE-2025-41380: Uncovered critical cryptographic flaws in maritime satellite communication terminals allowing key extraction and unsigned malicious firmware loading over satellite links.
CVE-2024-0674 & CVE-2024-0675: Root privilege escalation and local kiosk breakout via arbitrary update script manipulation in Bitcoin ATM terminal software.
CVE-2024-2414, CVE-2024-2415, CVE-2024-5785, CVE-2024-5786: Unauthenticated command injection and authentication bypass vulnerabilities in nationwide telecommunications routers.