Scworld
HP ThinPro Vulnerability Exposes Disk Encryption to Physical Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in HP ThinPro 8 and 9 allows attackers with physical access to bypass TPM-backed full-disk encryption. Discovered by researcher Darren McDonald in early 2026, the flaw enables attackers to modify the initramfs script, leading to the recovery of the LUKS encryption key. This zero-day vulnerability remains unpatched as of August 8, 2026. Affected devices include HP t530 and t540 thin clients. Organizations using ThinPro are advised to enhance security measures, including enabling Secure Boot and setting BIOS passwords. The vulnerability poses significant risks for data protection, especially for devices outside organizational control.
Key Points: • HP ThinPro 8 and 9 have a critical vulnerability allowing bypass of disk encryption. • Attackers can exploit the flaw by modifying the initramfs script with physical access. • Organizations are urged to implement additional security measures to protect sensitive data.