Security News

Microsoft plans to boot security vendors out of the Windows kernel
2024-11-19 18:43

Microsoft has announced the Windows Resiliency Initiative, aimed at avoiding a repeat of the prolonged worldwide IT outage caused by a buggy CrowdStrike update that took down millions of Windows...

PKfail Secure Boot bypass remains a significant risk two months later
2024-09-17 13:32

Roughly nine percent of tested firmware images use non-production cryptographic keys that are publicly known or leaked in data breaches, leaving many Secure Boot devices vulnerable to UEFI bootkit...

Microsoft shares temp fix for Linux boot issues on dual-boot systems
2024-08-23 18:02

Microsoft shared a workaround for Linux boot issues triggered by August security updates on dual-boot systems with Secure Boot enabled [...]

Microsoft: August updates cause Windows Server boot issues, freezes
2024-08-22 17:14

Microsoft has confirmed and fixed a known issue causing performance issues, boot problems, and freezes on Windows Server 2019 systems after installing the August 2024 security updates. [...]

Microsoft confirms August updates break Linux boot in dual-boot systems
2024-08-22 16:30

Microsoft has confirmed the August 2024 Windows security updates are causing Linux booting issues on dual-boot systems with Secure Boot enabled. [...]

August Windows security update breaks dual boot on Linux systems
2024-08-20 16:28

According to user reports following this month's Patch Tuesday, the August 2024 Windows security updates are breaking dual boot on some Linux systems with Secure Boot enabled. [...]

August Windows updates break dual boot on some Linux systems
2024-08-20 16:28

According to user reports following this month's Patch Tuesday, the August 2024 Windows updates are breaking dual boot on some Linux systems with Secure Boot enabled. [...]

Secure Boot useless on hundreds of PCs from major vendors after key leak
2024-07-29 01:58

Infosec in brief Protecting computers' BIOS and the boot process is essential for modern security - but knowing it's important isn't the same as actually taking steps to do it. Take the research published last week by security boffins at firmware security vendor Binarily.

Compromising the Secure Boot Process
2024-07-26 16:21

On Thursday, researchers from security firm Binarly revealed that Secure Boot is completely compromised on more than 200 device models sold by Acer, Dell, Gigabyte, Intel, and Supermicro. The cause: a cryptographic key underpinning Secure Boot on those models that was compromised in 2022.

PKfail Secure Boot bypass lets attackers install UEFI malware
2024-07-25 21:42

Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows attackers to bypass Secure Boot and install malware. As the Binarly Research Team found, affected devices use a test Secure Boot "Master key"-also known as Platform Key-generated by American Megatrends International, which was tagged as "DO NOT TRUST" and that upstream vendors should've replaced with their own securely generated keys.