11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers at ESET have discovered 11 old, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot protections on…
Cybersecurity researchers at ESET have discovered 11 old, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot protections on…
CVE-2026-10797 refers to a long-patched issue in UEFI shim that allowed the certificate-based revocation mechanism to be bypassed by modifying the second-stage…
Bootkitty is a UEFI bootkit that can be deployed by exploiting vulnerable UEFI shim bootloaders to bypass Secure Boot and gain persistent…
HybridPetya is a UEFI bootkit that can be deployed by exploiting vulnerable UEFI shim bootloaders to bypass Secure Boot and gain persistent…
BlackLotus is a UEFI bootkit that can be deployed by exploiting vulnerable UEFI shim bootloaders to bypass Secure Boot and gain persistent…
Researchers at firmware security firm Binarly have discovered six new vulnerabilities in U-Boot, the widely used bootloader for devices ranging from home…
A vulnerability in U-Boot's FIT image signature verification allowed a tampered image to swap in unsigned components, bypassing integrity checks. Patched in…
The CERT Coordination Center issued an advisory about the vendor-specific bootloaders not being updated to address vulnerabilities in the upstream shim project.
This week's cybersecurity landscape highlighted significant threats including a new Linux kernel flaw, AI-assisted malware, and active exploitation of critical vulnerabilities. The…
CVE-2026-8863 is a vulnerability in old Microsoft-signed UEFI shim bootloaders that allows attackers to bypass Secure Boot protections and execute arbitrary code…