vulnerability Long-Lived Vulnerability in Microsoft Secure Boot A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsigned shims – used to extend Secure Boot to Linux – could be easily bypassed, allowing attackers to d… Schneier on Security · Jul 29, 2026 High firmwareshimuefi
threat-intel Old UEFI Shims Expose Systems to Secure Boot Bypass A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating ba… SecurityWeek · Jul 16, 2026 High CVE-2026-8863CVE-2026-10797uefisecure bootvulnerability
threat-intel Forgotten Bootloaders Expose Secure Boot Blind Spot Researchers discovered 11 vulnerable, but still trusted, UEFI shim bootloaders that could have been used to bypass Secure Boot on systems relying on Microsoft's third-party UEFI signing certificate. Despite being outdate… Dark Reading · Jul 15, 2026 High secure bootfirmwareuefi
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability Forgotten UEFI shims undermining Secure Boot Researchers at ESET discovered 11 old, Microsoft-signed UEFI shim bootloaders from 2026-02-16 that could bypass UEFI Secure Boot on most systems. These shims, used by various software packages, allowed attackers to deplo… WeLiveSecurity · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797CVE-2020-10713uefisecure bootrevocation
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
vulnerability ABB B&R PCs This CISA advisory details a vulnerability (CVE-2023-45229 through CVE-2023-45237) affecting ABB B&R PCs, specifically versions of the EDK2 Network Package. The vulnerability, a critical out-of-bounds read, allows for re… CISA Advisories · May 21, 2026 Critical CVE-2023-45229CVE-2023-45230CVE-2023-45231uefidhcpv6remote code execution