# Windows 11 BitLocker Zero-Day, TeamPCP Malware Leak, Iran Gas Station Hacks | Cybersecurity Today Page: https://stenobird.com/podcast/cybersecurity-today-65508/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today Text version: https://stenobird.com/podcast/cybersecurity-today-65508/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-05-20T03:07:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/Cybersecurity_Today_May_20_2026.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today Duration seconds: 790 ## Resource A serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. David Shipley breaks down four major cybersecurity stories on Cybersecurity Today. First, a newly disclosed zero-day dubbed YellowKey reportedly defeats default Windows 11 BitLocker protection on systems using TPM-only encryption, giving attackers with physical access a path to unencrypted data through the Windows Recovery Environment. Microsoft is investigating, while security experts are urging stronger BitLocker configurations. The episode also examines the TeamPCP threat group's decision to release offensive tooling publicly, dramatically lowering the barrier for copycat supply-chain attacks. Researchers have already spotted malicious NPM packages borrowing similar techniques, including persistence mechanisms aimed at developer environments such as Visual Studio Code and Claude Code. David also looks at disturbing analysis of the FAST16 malware, which researchers believe was engineered to tamper with nuclear weapons simulation software including LS-DYNA and AutoDyn. And finally, U.S. officials reportedly suspect Iranian actors in cyberattacks targeting internet-exposed gas station automatic tank gauge systems, a reminder that weak operational technology security can quickly become a real-world infrastructure problem. 00:00 Sponsor Message 00… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/windows-11-bitlocker-zero-day-teampcp-malware-leak-iran-gas-station-hacks-cybersecurity-today.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.