PKfail Secure Boot bypass lets attackers install UEFI malware
ID: 7feab08c-a370-5c60-881a-356ba57f56d8
STIX ID: report--7feab08c-a370-5c60-881a-356ba57f56d8
Feed Name: Bleeping Computer
Binarly disclosed a critical UEFI firmware supply-chain issue named PKfail: many OEMs shipped devices using an AMI test Platform Key tagged "DO NOT TRUST," and leaked private keys (including AMI and MSI artifacts) enable attackers to manipulate KEK/db/dbx to bypass Secure Boot and sign persistent UEFI malware (examples: CosmicStrand, BlackLotus). The issue affects nearly 900 products across vendors such as Acer, Dell, HP, Intel, Lenovo, and Supermicro, spans firmware releases from 2012–2024, and Binarly published an advisory and a pk.fail scanning service while recommending key management best practices and firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
