logo

PKfail Secure Boot bypass remains a significant risk two months later

ID: fc369d58-c02d-5d00-a5f6-9f2a2db6c1c8

STIX ID: report--fc369d58-c02d-5d00-a5f6-9f2a2db6c1c8

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-09-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** The report details PKfail (CVE-2024-8105), a supply-chain Secure Boot vulnerability caused by use of publicly known or leaked test Platform Keys in firmware from many major vendors; Binarly's scanner identified 791 vulnerable submissions out of 10,095, and the flaw can allow attackers to bypass Secure Boot and install undetectable UEFI malware. Vendors have issued advisories and firmware updates to remove or replace affected keys; mitigations include applying vendor BIOS/firmware updates or isolating unsupported devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.