PKfail Secure Boot bypass remains a significant risk two months later
ID: fc369d58-c02d-5d00-a5f6-9f2a2db6c1c8
STIX ID: report--fc369d58-c02d-5d00-a5f6-9f2a2db6c1c8
Feed Name: Bleeping Computer
**Executive summary:** The report details PKfail (CVE-2024-8105), a supply-chain Secure Boot vulnerability caused by use of publicly known or leaked test Platform Keys in firmware from many major vendors; Binarly's scanner identified 791 vulnerable submissions out of 10,095, and the flaw can allow attackers to bypass Secure Boot and install undetectable UEFI malware. Vendors have issued advisories and firmware updates to remove or replace affected keys; mitigations include applying vendor BIOS/firmware updates or isolating unsupported devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
