logo

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

ID: 1032e1a6-e7ad-57ef-a182-78d64ed67035

STIX ID: report--1032e1a6-e7ad-57ef-a182-78d64ed67035

Feed Name: Ars Technica Security (category)

Threat Score
70/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Dan Goodin

...
...

ESET identified a set of signed UEFI "shim" binaries that are vulnerable or misconfigured such that they can bypass Secure Boot on Windows and Linux systems; some shims sign binaries with known CVEs (e.g., CVE-2015-5381), revocation and enforcement mechanisms are inadequate, and the issue exposes a long-standing systemic weakness in the Secure Boot trust model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.