Markets.Businessinsider HP Launches TPM Guard to Combat Physical TPM Bus Attacks
Article Content
- •HP TPM Guard prevents physical TPM bus attacks that can bypass BitLocker encryption.
- •The solution creates an encrypted connection between the TPM and CPU, enhancing security.
- •Available as a firmware update in July 2026, it will be free for selected HP G2 commercial PCs.
On March 24, 2026, HP announced the launch of HP TPM Guard at the HP Imagine 2026 event. This hardware solution aims to prevent physical TPM bus attacks that can bypass BitLocker drive encryption, a vulnerability that allows attackers with physical access to a device to intercept encryption keys using inexpensive hardware. The TPM Guard creates an encrypted tunnel between the Trusted Platform Module (TPM) and the CPU, making it inoperable if tampered with. This innovation is particularly significant for enterprises and organizations handling sensitive data, as it addresses a critical security gap. HP plans to offer TPM Guard as a firmware update starting in July 2026 for select HP G2 commercial PCs at no extra cost. The company has also proposed this technology to the Trusted Computing Group (TCG) to establish it as an industry standard. The announcement comes amid HP's stock trading near a 52-week low, highlighting the importance of security innovations in maintaining market confidence.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…