logo

PKfail Secure Boot bypass lets attackers install UEFI malware

ID: 7feab08c-a370-5c60-881a-356ba57f56d8

STIX ID: report--7feab08c-a370-5c60-881a-356ba57f56d8

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-07-25

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Binarly disclosed a critical UEFI firmware supply-chain issue named PKfail: many OEMs shipped devices using an AMI test Platform Key tagged "DO NOT TRUST," and leaked private keys (including AMI and MSI artifacts) enable attackers to manipulate KEK/db/dbx to bypass Secure Boot and sign persistent UEFI malware (examples: CosmicStrand, BlackLotus). The issue affects nearly 900 products across vendors such as Acer, Dell, HP, Intel, Lenovo, and Supermicro, spans firmware releases from 2012–2024, and Binarly published an advisory and a pk.fail scanning service while recommending key management best practices and firmware updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.