NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / New vulnerability affects over 200 PC models from major brands
    Summarize
    Next Article
    New vulnerability affects over 200 PC models from major brands
    Secure Boot security standard has been compromised by PKfail

    New vulnerability affects over 200 PC models from major brands

    By Akash Pandey
    Jul 29, 2024
    12:58 pm

    What's the story

    A new vulnerability, known as PKfail, has compromised Secure Boot, a security standard developed by the PC industry.

    Cybersecurity firm Binarly reported that this breach, caused by a leaked cryptographic key, has affected over 200 product models from several major brands.

    The leak originated from an employee who accidentally posted source code containing the encrypted platform key for Secure Boot on a public GitHub repo in late 2022. The code was protected with a 4-character password that was easily cracked.

    Brands affected

    Dell and Intel among brands impacted by the breach

    The compromised platform key, discovered by Binarly in January 2023, was found to be reused across hundreds of product lines from major tech brands such as Acer, Dell, Gigabyte, Intel, and Supermicro.

    The vulnerability affects both x86 and Arm devices.

    This breach allows malicious actors to bypass Secure Boot by signing malicious code and loading harmful firmware implants like BlackLotus.

    Windows 11 security

    Microsoft's Secure Boot requirement raises concerns

    Microsoft's decision to make Secure Boot a requirement for Windows 11 has sparked concerns in light of these findings.

    The company has been advocating this technology for years to protect systems against BIOS rootkits.

    Binarly's analysis of UEFI firmware images dating back to 2012 revealed that over 10% were impacted by using these untrusted keys instead of manufacturer-generated secure ones as intended.

    In the past four years alone, 8% of firmware still had this issue.

    Vendor missteps

    Supply chain failures exposed

    The incident has exposed significant supply chain failures and highlighted how some vendors have mishandled critical platform security.

    Issues include reusing the same keys across consumer and enterprise device lines, shipping products with non-production cryptographic material, and failing to rotate keys regularly.

    Binarly pointed out these security problems related to device supply chain security that led to this breach.

    Security recommendations

    Binarly advises on mitigating Secure Boot vulnerability

    Binarly urges device owners and IT administrators to check if their equipment is listed in their vulnerability advisory and promptly apply any related firmware patches from their vendor.

    The firm also recommends that device vendors follow best practices for cryptographic key management, such as using Hardware Security Modules, and replace any test keys provided with securely generated keys.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Microsoft
    Windows 11

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Microsoft

    'Skeleton key' vulnerability found in AI tools, Microsoft urges caution Artificial Intelligence and Machine Learning
    Apple to join OpenAI board as observer following AI partnership Apple
    Microsoft's latest layoff round hits product teams Layoff News
    Indian prices for Microsoft Surface Laptop 7, Pro 11 leaked Technology

    Windows 11

    Windows 11 now lets you write instead of typing inputs Microsoft
    Lenovo Legion Go handheld gaming console might launch in India Lenovo
    ASUS Zenbook 14 OLED laptop breaks cover: Check features Asus
    Microsoft warns outdated Teams versions might cause disruptions Microsoft
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025