* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, November 6, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Trixie Mattel to share journey in entertainment, advocacy at UW–Madison – WKOW

    Trixie Mattel to Share Her Inspiring Journey in Entertainment and Advocacy at UW-Madison

    Cleveland State to Broadcast Six Basketball Games on Rock Entertainment Sports Network – csuvikings.com

    Cleveland State to Broadcast Six Basketball Games on Rock Entertainment Sports Network – csuvikings.com

    Can Caesars Entertainment’s (CZR) Investment in Digital Offset Las Vegas Weakness? – simplywall.st

    How do you spell success? ‘Spelling Bee’ lands at Surfside Playhouse – Florida Today

    How Do You Spell Success? Catch ‘Spelling Bee’ Live at Surfside Playhouse!

    Belmont Names Debbie Carroll Head of New Center for Mental Health in Entertainment – Billboard

    Debbie Carroll Named Leader of Groundbreaking New Center for Mental Health in Entertainment

    Call of Duty Movie’s Plot Setting Revealed in New Rumor – Yahoo

    Exciting New Rumor Reveals the Plot Setting of the Call of Duty Movie!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    How We Lost Ourselves to Technology—and How We Can Come Back – The Free Press

    How Technology Took Over Our Lives-and How We Can Take Back Control

    Sleeper Picks: World Wide Technology Championship – PGA Tour

    Discover the Ultimate Sleeper Picks for the World Wide Technology Championship

    Rowland.ai Named Disruptive Technology of the Year by The Energy Council – GlobeNewswire

    Rowland.ai Named Disruptive Technology of the Year by Industry Leaders

    Peraton Honored As Silver Stevie® Award Winner in 2025 Stevie Awards for Technology Excellence – The AI Journal

    Peraton Honored As Silver Stevie® Award Winner in 2025 Stevie Awards for Technology Excellence – The AI Journal

    [News] China Makes Breakthrough in Chip Technology, Paving the Way for Lithography Advancements – TrendForce

    [News] China Makes Breakthrough in Chip Technology, Paving the Way for Lithography Advancements – TrendForce

    Can RFID technology solve the global medicine shortage crisis? – World Health Expo

    Can RFID technology solve the global medicine shortage crisis? – World Health Expo

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Trixie Mattel to share journey in entertainment, advocacy at UW–Madison – WKOW

    Trixie Mattel to Share Her Inspiring Journey in Entertainment and Advocacy at UW-Madison

    Cleveland State to Broadcast Six Basketball Games on Rock Entertainment Sports Network – csuvikings.com

    Cleveland State to Broadcast Six Basketball Games on Rock Entertainment Sports Network – csuvikings.com

    Can Caesars Entertainment’s (CZR) Investment in Digital Offset Las Vegas Weakness? – simplywall.st

    How do you spell success? ‘Spelling Bee’ lands at Surfside Playhouse – Florida Today

    How Do You Spell Success? Catch ‘Spelling Bee’ Live at Surfside Playhouse!

    Belmont Names Debbie Carroll Head of New Center for Mental Health in Entertainment – Billboard

    Debbie Carroll Named Leader of Groundbreaking New Center for Mental Health in Entertainment

    Call of Duty Movie’s Plot Setting Revealed in New Rumor – Yahoo

    Exciting New Rumor Reveals the Plot Setting of the Call of Duty Movie!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    How We Lost Ourselves to Technology—and How We Can Come Back – The Free Press

    How Technology Took Over Our Lives-and How We Can Take Back Control

    Sleeper Picks: World Wide Technology Championship – PGA Tour

    Discover the Ultimate Sleeper Picks for the World Wide Technology Championship

    Rowland.ai Named Disruptive Technology of the Year by The Energy Council – GlobeNewswire

    Rowland.ai Named Disruptive Technology of the Year by Industry Leaders

    Peraton Honored As Silver Stevie® Award Winner in 2025 Stevie Awards for Technology Excellence – The AI Journal

    Peraton Honored As Silver Stevie® Award Winner in 2025 Stevie Awards for Technology Excellence – The AI Journal

    [News] China Makes Breakthrough in Chip Technology, Paving the Way for Lithography Advancements – TrendForce

    [News] China Makes Breakthrough in Chip Technology, Paving the Way for Lithography Advancements – TrendForce

    Can RFID technology solve the global medicine shortage crisis? – World Health Expo

    Can RFID technology solve the global medicine shortage crisis? – World Health Expo

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

PKfail Secure Boot bypass lets attackers install UEFI malware

July 27, 2024
in Technology
PKfail Secure Boot bypass lets attackers install UEFI malware
Share on FacebookShare on Twitter

PKfail

Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows attackers to bypass Secure Boot and install malware.

As the Binarly Research Team found, affected devices use a test Secure Boot “master key”—also known as Platform Key (PK)—generated by American Megatrends International (AMI), which was tagged as “DO NOT TRUST” and that upstream vendors should’ve replaced with their own securely generated keys.

“This Platform Key, which manages the Secure Boot databases and maintains the chain of trust from firmware to the operating system, is often not replaced by OEMs or device vendors, resulting in devices shipping with untrusted keys,” the Binarly Research Team said.

The UEFI device makers who used untrusted test keys across 813 products include Acer, Aopen, Dell, Formelife, Fujitsu, Gigabyte, HP, Intel, Lenovo, and Supermicro.

Vulnerable Intel firmwareVulnerable Intel firmware (BleepingComputer)

In May 2023, Binarly discovered a supply chain security incident involving leaked private keys from Intel Boot Guard, impacting multiple vendors. As first reported by BleepingComputer, the Money Message extortion gang leaked MSI source code for firmware used by the company’s motherboards.

The code contained image signing private keys for 57 MSI products and Intel Boot Guard private keys for another 116 MSI products.

Earlier this year, a private key from American Megatrends International (AMI) related to the Secure Boot “master key” was also leaked, affecting various enterprise device manufacturers. The impacted devices are still in use, and the key is being used in recently released enterprise devices.

PKfail impact and recommendations

As Binarly explains, successfully exploiting this issue allows threat actors with access to vulnerable devices and the private part of the Platform Key to bypass Secure Boot by manipulating the Key Exchange Key (KEK) database, the Signature Database (db), and the Forbidden Signature Database (dbx).

After compromising the entire security chain, from firmware to the operating system, they can sign malicious code, which allows them to deploy UEFI malware like CosmicStrand and BlackLotus.

“The first firmware vulnerable to PKfail was released back in May 2012, while the latest was released in June 2024. Overall, this makes this supply-chain issue one of the longest-lasting of its kind, spanning over 12 years,” Binarly added.

“The list of affected devices, which at the moment contains almost 900 devices, can be found in our BRLY-2024-005 advisory. A closer look at the scan results revealed that our platform extracted and identified 22 unique untrusted keys.”

To mitigate PKfail, vendors are advised to generate and manage the Platform Key by following cryptographic key management best practices, such as Hardware Security Modules.

It’s also essential to replace any test keys provided by independent BIOS vendors like AMI with their own safely generated keys.

Users should monitor firmware updates issued by device vendors and apply any security patches addressing the PKfail supply-chain issue as soon as possible.

Binarly also published the pk.fail website, which helps users scan firmware binaries for free to find PKfail-vulnerable devices and malicious payloads.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/pkfail-secure-boot-bypass-lets-attackers-install-uefi-malware/

Tags: PKfailsecuretechnology
Previous Post

Italy’s flagbearer issues grovelling apology to wife after losing wedding ring in opening ceremony

Next Post

Russian ransomware gangs account for 69% of all ransom proceeds

Recycling Reform Act – Washington State Department of Ecology (.gov)

Washington State Launches Ambitious Recycling Reform to Revolutionize Waste Management

November 6, 2025
Science of the Stench: Why CSU’s corpse flower smells so foul – The Rocky Mountain Collegian

The Science Behind CSU’s Corpse Flower: Unraveling the Mystery of Its Foul Smell

November 6, 2025
Astronomer reveals first look at Comet 3I/ATLAS as it reappears from behind the sun – Live Science

Astronomer Unveils Stunning First Glimpse of Comet 3I/ATLAS Emerging from Behind the Sun

November 6, 2025
TikTok of Chow Chow Puppy’s First 6 Months Is Melting Hearts – Yahoo

Irresistible Chow Chow Puppy’s First 6 Months Melt Hearts Worldwide

November 6, 2025
Why Does Doing Hard Things Outside Feel So Rewarding? Outdoor Adventures Change Our Brains. – Outside Magazine

How Conquering Outdoor Challenges Transforms Your Brain and Boosts Your Well-Being

November 6, 2025
Dynamic and dangerous vs. Dortmund, Foden must be part of England’s World Cup squad – ESPN

Dynamic and Dangerous vs. Dortmund: Why Foden Must Be in England’s World Cup Squad

November 6, 2025
Democrats tap anxiety over Trump’s economy in victories that signal midterm strategy – USA Today

Democrats Leverage Economic Worries Over Trump to Secure Crucial Midterm Victories

November 6, 2025
Trixie Mattel to share journey in entertainment, advocacy at UW–Madison – WKOW

Trixie Mattel to Share Her Inspiring Journey in Entertainment and Advocacy at UW-Madison

November 6, 2025
Iowa seeks federal funding to support rural health care, Gov. Kim Reynolds announces – Iowa Capital Dispatch

Iowa Launches Bold Effort to Secure Federal Funds for Boosting Rural Health Care, Governor Kim Reynolds Reveals

November 6, 2025
Federal judge warns Justice Department it may be veering close to mishandling evidence in Comey case – CNN

Federal judge warns Justice Department it may be veering close to mishandling evidence in Comey case – CNN

November 6, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (905)
  • Economy (926)
  • Entertainment (21,798)
  • General (18,020)
  • Health (9,967)
  • Lifestyle (939)
  • News (22,149)
  • People (928)
  • Politics (937)
  • Science (16,138)
  • Sports (21,427)
  • Technology (15,906)
  • World (910)

Recent News

Recycling Reform Act – Washington State Department of Ecology (.gov)

Washington State Launches Ambitious Recycling Reform to Revolutionize Waste Management

November 6, 2025
Science of the Stench: Why CSU’s corpse flower smells so foul – The Rocky Mountain Collegian

The Science Behind CSU’s Corpse Flower: Unraveling the Mystery of Its Foul Smell

November 6, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version