Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
BlackLotus
Malware
BlackLotus
MITRE ATT&CK TTPs
1
T1059.001
PowerShell
Execution
Source Articles
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have identified 11 outdated, Microsoft-signed UEFI shim bootloaders that can be exploited to bypass Secure Boot protections on UEFI-based systems. These vulnerable shims allow attackers to execute arbitrary code during the early boot phase, enabling deployment of persistent UEFI bootkits such as Bootkitty and BlackLotus. Although the Microsoft Corporation UEFI CA 2011 certificate expired in June 2026, affected systems remain at risk if the vulnerable shims are not explicitly revoked via hash. The issue highlights a supply chain exposure where outdated but still-trusted bootloaders undermine critical firmware security mechanisms.
hacker-news
·
2w ago