logo

LABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management

Threat Score
85/100

Date Published: 2024-12-03

Date Updated: 2026-07-27

Author: LABScon

...
...

This report summarizes a presentation on "PKfail," a UEFI firmware supply-chain vulnerability caused by vendors shipping default test Platform Keys (PK) in Secure Boot implementations; leaked test keys allow attackers to bypass Secure Boot and deploy persistent firmware bootkits (e.g., BlackLotus) across hundreds of affected device models, based on an extensive analysis of UEFI firmware images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.