The Chonkerton

Long-Lived Vulnerability in Microsoft Secure Boot

tech

Microsoft's Secure Boot — the anti-malware protection embedded in Windows and Linux device firmware — has been trivially bypassable for thirteen of its fourteen years of existence. ESET researchers discovered the flaw: Microsoft failed to revoke outdated firmware images called shims after vulnerabilities were identified in them, some dating back to twenty thirteen. That means novice hackers could use publicly available code to completely bypass the protection. The lapse exposes a critical weakness in Microsoft's management of the signing system it oversees.

Source: https://www.schneier.com/blog/archives/2026/07/long-lived...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton