Hack.lu 2026

Mohamed Ouad

Mohamed Ouad is a Senior Security Consultant focused on web apps and cloud infrastructure. Mohamed garnered his professional security experience at NTT Data Italy. There, he was involved in penetration testing and vulnerability assessments for critical insurance and telecommunications companies. During his research and bug bounty activities, Mohamed has been recognized by numerous companies including: Microsoft's MSRC, Kaspersky, the Dutch Cancer Society, Symantec, and ESET. He has also discovered multiple security vulnerabilities across various open-source projects, contributing responsible disclosures that helped strengthen their overall security posture.


Session

10-20
14:45
30min
Glucose in the Air: Wireless Medical IoT Without a Trust Anchor
Mohamed Ouad, Bartek Górkiewicz

Continuous glucose monitors (CGMs) stream health information over Bluetooth Low Energy from body-worn sensors to smartphones and the vendors’ clouds. Millions of people depend on this communication system every day. However, existing CGM regulations tend to focus on medical-device compliance and operational requirements, while their security posture as connected medical IoT devices is often not fully evaluated.

Over a two-month research effort, we conducted a comparative security assessment of four commercial continuous glucose monitoring (CGM) sensors, covering wireless pairing mechanisms, mobile applications, embedded interfaces, and portions of the supporting cloud infrastructure. Across multiple vendors, we identified recurring architectural weaknesses affecting user device trust, communication security, sensor management functionality, and backend authorization controls.

Guided by a detailed threat model, we analyzed both the design and implementation decisions behind these platforms. In this talk, we will demonstrate how attackers in close proximity can abuse weaknesses in device pairing and trust establishment to impersonate trusted devices, why protocol obscurity at the wireless layer fails as a security boundary, and what manufacturers must change to build secure CGM ecosystems.

Attendees will leave with a clear understanding of the relevant threat scenarios, the technical flaws introduced during the design and manufacturing of these devices, and the broader implications such weaknesses have in today’s always-connected society. The talk will also highlight how insecure wireless connectivity, weak trust assumptions, and poor security engineering practices can directly impact the safety, privacy, and reliability of modern medical ecosystems.

topic: hack.lu
Europe