logo

New Windows updates replace expiring Secure Boot certificates

ID: 56e9c027-f0c6-5e45-9af3-84422ba1c75c

STIX ID: report--56e9c027-f0c6-5e45-9af3-84422ba1c75c

Feed Name: Bleeping Computer

Date Published: 2026-01-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft announced that Windows quality updates will automatically deliver new Secure Boot certificates to eligible Windows 11 24H2/25H2 systems before expirations beginning June 2026, ensuring only trusted bootloaders can run and preserving Secure Boot protections. Organizations should inventory devices, verify Secure Boot status, apply OEM firmware updates, and deploy the certificates via Windows Update or enterprise controls (registry, WinCS, Group Policy) to avoid losing pre-boot security updates and boot integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.