AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.
Curated threat research and citations from CrowdStrike, Mandiant, Microsoft, and other sources — unlock with Premium.
Upgrade to Premium