Gabriel González García
Hardware Security Researcher
Published Author Embedded & Hardware Security
Featured Publication

Attacking and Securing U-Boot

The definitive hands-on technical guide to uncovering, exploiting, and fixing vulnerabilities in embedded bootloaders.

Attacking and Securing U-Boot Book Cover
Comprehensive Practical Guide

Attacking and Securing U-Boot

U-Boot is the de facto bootloader for millions of embedded systems, IoT devices, automotive ECUs, and SATCOM terminals worldwide. This book provides direct technical methodologies to audit, exploit, and remediate corner-case vulnerabilities and misconfigurations in production deployments.

  • Bootloader architecture & verified boot
  • Real-world attack scenarios & exploits
  • Dedicated Virtual Machine hands-on labs
  • Hardening playbooks for engineering teams

Get the Hands-On Virtual Machine (VM) & Lab Firmware

Subscribe to receive the companion Virtual Machine, firmware images, exercises, and updates when new embedded security research is published.

Engineering & Tooling

Flagship Tools & Open Source Hardware

Custom native tools, entropy generators, and glitching platforms built to solve real-world reverse engineering bottlenecks.

Native Tool

GabriHex

A high-performance, native hex editor engineered for massive firmware dumps, binary analysis, and real-time pattern inspection.

  • Repeating Row Collapsing: Cleans padding without clutter
  • Magic Signature Check: Integrated binwalk-style scanner
  • Zero Virtual Scroll Latency: Processes chunks in 256KB
macOS • Windows • Linux Explore & Download →
Quantum Physics

QRNGabri

Authentic Quantum Random Number Generator deriving cryptographic entropy from the fundamental radioactive alpha-decay of Radon-222.

  • Radon-222 Decay Timing: Nature's true unpredictable entropy
  • Slow-Clock LSB Extraction: Ultra-low correlation extractor
  • ESP32-S3 BLE Platform: Hardware stream & Von Neumann de-bias
Hardware + Dashboard Live Entropy Demo →
Executive Strategy

Hardware Security as Business Risk

Why silicon, firmware, and physical-layer decisions directly dictate corporate liability, recall costs, and brand continuity.

Vulnerability Research

Deep-Dive Whitepapers & Exploit Analysis

Original security research, hardware glitching experiments, and satellite communications audits.

View All 13+ Articles →
Conference Talks & Keynotes

Public Research & Presentations

Technical talks, hardware exploit demonstrations, and zero-day disclosures delivered at major international cybersecurity conferences through the years.

RootedCON 2026 📍 Madrid, Spain

SATCOM: Attacker's Perspective

Comprehensive exploration of practical satellite communication exploitation vectors—covering ground-level RF sidelobe interception, hardware terminal reverse engineering, and satellite uplink telemetry vulnerabilities.

RootedCON 2025 📍 Madrid, Spain

Owning a Bitcoin ATM

Presented live teardowns and zero-day vulnerabilities (CVE-2024-0674 / CVE-2024-0675) in Lamassu Douro Bitcoin ATMs with Dani Martinez, showcasing bus tapping, tamper bypasses, and root compromise via malicious QR codes.

SPACE Hackathon 2025 📍 Madrid, Spain

Aerospace & Satellite Hardware Security

Keynote presentation and technical mentoring on satellite terminal vulnerabilities, ground-station RF sidelobe interception, and hardening embedded avionics against physical and wireless exploits.

Black Hat USA 2025 📍 Las Vegas, USA

Glitch.IO: Open-Source Framework for Fault Injection Attacks

Presented Glitch.IO at Black Hat Arsenal—an open-source, high-performance hardware and software framework designed for automated voltage and electromagnetic fault injection (EMFI) and rapid glitch parameter exploration on embedded targets.

RootedCON 2024 📍 Madrid, Spain

Applying Fault Injection to Drone Firmware Updates

Demonstrated how precision hardware power glitching subverts cryptographic signature verification during in-field UAV firmware updates, enabling persistent unsigned code execution on drone flight controllers.

CRIPTOREDTALKS 2024 📍 Madrid, Spain

"Boot to Root": Bootloader Vulnerabilities & Exploitation

In-depth exploration of low-level bootloader security flaws and U-Boot misconfigurations in embedded Linux systems, detailing practical breakout vectors from restricted boot sequences into full root execution.

Black Hat Europe 2016 📍 London, UK

Hacking the Analog World: Insecurity in Industrial ADCs

Uncovered critical sensory manipulation attacks against Analog-to-Digital Converters (ADCs) deployed in industrial control systems (ICS/SCADA) and smart grid power monitoring infrastructure.

Hackito Ergo Sum 2011 📍 Paris, France

Man-In-Remote: PKCS#11 for Fun and Non-Profit

Pioneering research into PKCS#11 cryptographic middleware vulnerabilities and smart card proxying, demonstrating remote identity exploitation of the Spanish Electronic National ID (DNIe).

RootedCON 2011 📍 Madrid, Spain

Man-In-Remote: PKCS#11 & DNIe Exploitation

National conference presentation analyzing security weaknesses in cryptographic hardware middleware and presenting tools for remote token tunneling and digital signature hijacking.

Conference Keynotes & Technical Executive Briefings

Gabriel delivers conference keynotes and provides strategic technical insights. For penetration testing, hardware security audits, and professional services, engagements are conducted exclusively through IOActive.

Inquire via LinkedIn ↗ IOActive Services ↗
About Gabriel

Pioneering Embedded & Hardware Security

Over 20 years uncovering zero-day vulnerabilities in satellite communications, avionics, industrial smart grids, financial kiosks, and embedded microcontrollers.

Hi, I am Gabriel González García. Throughout my career, I have completed hundreds of advanced security assessments, physical hardware teardowns, reverse engineering investigations, and firmware exploitation engagements across the globe.

My pioneering research focuses on breaking down the boundaries between theoretical hardware flaws and practical real-world exploitation—spanning SATCOM RF sidelobe interception, physical power glitching on drone flight controllers, cryptographic bus tapping on Bitcoin ATMs, and smart grid controller exploitation.

🔬

Pioneering Research & Exploits

Published whitepapers and real-world teardowns

Demonstrated how sub-microsecond power glitching pulses subvert digital signature verification routines during in-field drone firmware updates, enabling persistent root compromise.

Audited physical bus interception, microswitch sensor bypasses, and software update flaws in Lamassu Bitcoin ATMs that allowed complete kiosk compromise and cash dispenser manipulation.

Reverse-engineered proprietary hardware cryptographic acceleration routines and AES-CCM wireless protocols within Nordic Semiconductor nRF SoCs, revealing implementation weaknesses in secure RF communications.

🛡️

Latest Published CVEs

Recent zero-day disclosures from ongoing active vulnerability research
Circutor Smart Grid Concentrators ↗ 12 CVEs (2 Critical, 10 High)

CVE-2025-11778 through CVE-2025-11789: Discovered multiple critical remote execution and authentication bypass vulnerabilities in SGE-PLC1000 & SGE-PLC50 industrial power grid concentrators.

CVE-2025-41377 to CVE-2025-41380: Uncovered critical cryptographic flaws in maritime satellite communication terminals allowing key extraction and unsigned malicious firmware loading over satellite links.

CVE-2024-0674 & CVE-2024-0675: Root privilege escalation and local kiosk breakout via arbitrary update script manipulation in Bitcoin ATM terminal software.

CVE-2024-2414, CVE-2024-2415, CVE-2024-5785, CVE-2024-5786: Unauthenticated command injection and authentication bypass vulnerabilities in nationwide telecommunications routers.

Connect on LinkedIn Explore Research Library Attacking & Securing U-Boot Book