Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Today’s NYT Connections: Sports Edition Hints, Answers for April 20 #574
    • Will Humans Live Forever? AI Races to Defeat Aging
    • AI evolves itself to speed up scientific discovery
    • Australia’s privacy commissioner tried, in vain, to sound the alarm on data protection during the u16s social media ban trials
    • Nothing Phone (4a) Pro Review: A Close Second
    • Match Group CEO Spencer Rascoff says growing women’s share on Tinder is his “primary focus” to stem user declines; Sensor Tower says 75% of Tinder users are men (Kieran Smith/Financial Times)
    • Today’s NYT Connections Hints, Answers for April 20 #1044
    • AI Machine-Vision Earns Man Overboard Certification
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Monday, April 20
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.
    News

    Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.

    Editor Times FeaturedBy Editor Times FeaturedJune 10, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Researchers have unearthed two publicly accessible exploits that utterly evade protections supplied by Safe Boot, the industry-wide mechanism for guaranteeing units load solely safe working system pictures in the course of the boot-up course of. Microsoft is taking motion to dam one exploit and permitting the opposite one to stay a viable menace.

    As a part of Tuesday’s month-to-month safety replace routine, Microsoft patched CVE-2025-3052, a Safe Boot bypass vulnerability affecting greater than 50 machine makers. Greater than a dozen modules that enable units from these producers to run on Linux enable an attacker with bodily entry to show off Safe Boot and, from there, go on to put in malware that runs earlier than the working system masses. Such “evil maid” assaults are exactly the menace Safe Boot is designed to forestall. The vulnerability can be exploited remotely to make infections stealthier and extra highly effective if an attacker has already gained administrative management of a machine.

    A single level of failure

    The underlying reason behind the vulnerability is a crucial vulnerability in a device used to flash firmware pictures on the motherboards of units offered by DT Analysis, a producer of rugged cell units. It has been available on VirusTotal since final 12 months and was digitally signed in 2022, a sign it has been accessible by different channels since a minimum of that earlier date.

    Though the module was meant to run on DT Analysis units solely, most machines working both Home windows or Linux will execute it in the course of the boot-up course of. That is as a result of the module is authenticated by “Microsoft Company UEFI CA 2011,” a cryptographic certificates that’s signed by Microsoft and comes preinstalled on affected machines. The aim of the certificates is to authenticate so-called shims for loading Linux. Producers set up it on their units to make sure they’re suitable with Linux. The patch Microsoft launched Tuesday provides cryptographic hashes for 14 separate variants of the DT Analysis device to a block checklist saved within the DBX, a database itemizing signed modules which were revoked or are in any other case untrusted.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Match Group CEO Spencer Rascoff says growing women’s share on Tinder is his “primary focus” to stem user declines; Sensor Tower says 75% of Tinder users are men (Kieran Smith/Financial Times)

    April 20, 2026

    Sources say NSA is using Mythos Preview, and a source says it is also being used widely within the DoD, despite Anthropic’s designation as a supply chain risk (Axios)

    April 19, 2026

    Vercel says it detected unauthorized access to its internal systems after a hacker using the ShinyHunters handle claimed a breach on BreachForums (Lawrence Abrams/BleepingComputer)

    April 19, 2026

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026

    Google is in talks with Marvell Technology to develop a memory processing unit that works alongside TPUs, and a new TPU for running AI models (Qianer Liu/The Information)

    April 19, 2026

    At the Beijing half-marathon, several humanoid robots beat human winners by 10+ minutes; a robot made by Honor beat the human world record held by Jacob Kiplimo (Reuters)

    April 19, 2026

    Comments are closed.

    Editors Picks

    Today’s NYT Connections: Sports Edition Hints, Answers for April 20 #574

    April 20, 2026

    Will Humans Live Forever? AI Races to Defeat Aging

    April 20, 2026

    AI evolves itself to speed up scientific discovery

    April 20, 2026

    Australia’s privacy commissioner tried, in vain, to sound the alarm on data protection during the u16s social media ban trials

    April 20, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Best Expert-Tested Workout Apps and Services for 2026

    February 9, 2026

    Can Machines Really Recreate “You”?

    August 22, 2025

    Prepare to Share All Your Pics With Meta If You Turn On Facebook’s New AI Photo Tool

    July 2, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.