#SecureBoot ist echt die Pest 💩
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.

The publicly available exploits provide a near-universal way to bypass key protections.

Ars Technica
Unified #Kernel Images in #openSUSE: stronger boot, simplified structure. 🔐 Register for the #openSUSE Conference and #learn more. #SecureBoot #Linux https://events.opensuse.org/
openSUSE Events

UEFI-BIOS-Lücken: SecureBoot-Umgehung und Firmware-Austausch möglich

Durch Nutzung unsicherer NVRAM-Variablen ermöglichen viele UEFI-BIOS-Versionen das Umgehen von SecureBoot oder Austausch der Firmware.

heise online

That's one way of going about that.

Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.

https://arstechnica.com/security/2025/06/unearthed-in-the-wild-2-secure-boot-exploits-microsoft-patches-only-1-of-them/

#SecureBoot #Microsoft #Patching #Security #Exploit #InfoSec #Tech

New Secure Boot flaw lets attackers install bootkit malware, patch now

Security researchers have disclosed a new Secure Boot bypass tracked as CVE-2025-3052 that can be used to turn off security on PCs and servers and install bootkit malware.

BleepingComputer
Not-So-Secure Boot: 2 Secure Boot Exploits Discovered

Secure Boot has long been advertised as the security boundary that keeps rogue software and untrusted code at bay during system startup. By checking...

Linux Security
Schwerwiegende Sicherheitslücken: Zwei Exploits können #SecureBoot komplett umgehen. #Microsoft hat bislang nur eine davon geschlossen - die zweite bleibt weiterhin ausnutzbar. https://winfuture.de/news,151480.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
Zwei Exploits gegen Secure Boot: Microsoft schließt nur eine Lücke

Zwei öffentlich zugängliche Exploits sind in der Lage, die Schutzmechanismen von Secure Boot vollständig zu umgehen. Microsoft hat bislang nur eine dieser Schwachstellen gepatcht, die andere bleibt weiterhin ausnutzbar.

WinFuture.de

#Hydroph0bia (CVE-2025-4275) - a trivial #SecureBoot bypass for UEFI-compatible firmware based on Insyde #H2O, part 1

https://coderush.me/hydroph0bia-part1/

Hydroph0bia (CVE-2025-4275) - a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O, part 1

Another Crack in the Chain of Trust: Uncovering (Yet Another) #SecureBoot Bypass

https://www.binarly.io/blog/another-crack-in-the-chain-of-trust

Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass

Binarly uncovers CVE-2025-3052: a Secure Boot bypass affecting most UEFI devices, enabling attackers to run unsigned code before OS load.