PKfail: 800+ Major PC Models have Insecure ‘Secure Boot’
ID: 9b09b7e8-c024-5fa5-8e3a-4411394b758d
STIX ID: report--9b09b7e8-c024-5fa5-8e3a-4411394b758d
Feed Name: Security Boulevard
Binarly's "PKfail" research reveals that dozens of major PC vendors (including HP, Lenovo, Dell, Intel, Acer, Gigabyte and others) shipped systems using non-private or test Platform Keys for UEFI Secure Boot, affecting hundreds of models (reports cite ~813 products). This supply-chain cryptographic key-management failure effectively undermines Secure Boot and enables attackers with device access to install persistent UEFI malware (examples: CosmicStrand, BlackLotus); recommended mitigations include rotating/removing test keys, using HSMs for key management, and applying firmware updates from vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
