Bootkit: the challenge of 2008Kaspersky Securelist·Dec 18, 10:00 UTC · Dec 18, 2008VulnerabilityCVE-2007-5659CVE-2006-0003CVE-2006-5820+9 CVEs35
BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
Source code of the BlackLotus UEFI Bootkit was leaked on GitHubSecurity Affairs·Jul 14, 21:31 UTC · Jul 14, 2023VulnerabilityCVE-2022-21894147
Windows and Linux users: The deadline to update Secure Boot keys is nearArs Technica · Security·Jun 17, 11:15 UTC · Jun 17, 2026Vulnerability155
Security researchers find another UEFI bootkit used for cyberThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability42
Researchers developed a new powerful BIOS bootkitSecurity Affairs·Mar 20, 12:08 UTC · Mar 20, 2015Vulnerability42
BlackLotus is first bootkit bypassing UEFI Secure Boot on Win 11Security Affairs·Mar 1, 20:57 UTC · Mar 1, 2023VulnerabilityCVE-2022-2189460
New MoonBounce UEFI bootkit can\'t be removed by replacing the hard driveThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability30
NSA Releases Guide to Combat Powerful BlackLotus Bootkit Targeting Windows SystemsThe Hacker News·Jun 24, 15:03 UTC · Jun 24, 2023VulnerabilityCVE-2022-21894CVE-2023-2493235
Researchers Discover UEFI Bootkit Targeting Windows Computers Since 2012The Hacker News·Oct 6, 06:33 UTC · Oct 6, 2021Vulnerability142
Underminer Exploit Kit spreading Bootkits and cryptocurrency minersSecurity Affairs·Jul 29, 08:54 UTC · Jul 29, 2018VulnerabilityCVE-2015-5119CVE-2016-0189CVE-2018-487835
Vulnerable firmware for Gigabyte motherboards could allow bootkit installationHelp Net Security·Jul 15, 00:00 UTC · Jul 15, 2025VulnerabilityCVE-2025-7029CVE-2025-7028CVE-2025-7027+1 CVEs35
New UEFI Secure Boot Vulnerability Could Allow Attackers to Load Malicious BootkitsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025VulnerabilityCVE-2024-734435
Critical vulnerability affecting most Linux distros allows for bootkitsArs Technica · Security·Feb 7, 01:37 UTC · Feb 7, 2024VulnerabilityCVE-2023-4054760
MosaicRegressor: Lurking in the Shadows of UEFIKaspersky Securelist·Oct 5, 10:00 UTC · Oct 5, 2020Vulnerability42
China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit HintsSecurity Affairs·Jun 17, 08:10 UTC · Jun 17, 2026VulnerabilityCVE-2023-2493247
Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security·May 9, 00:00 UTC · May 9, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2022-21882+10 CVEs160
NSA Releases Guide to Mitigate BlackLotus Bootkit InfectionsInfosecurity Magazine·Jun 26, 16:30 UTC · Jun 26, 2023VulnerabilityCVE-2022-2189435
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-1079747
Patch Tuesday, January 2026 EditionKrebs on Security·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2026-20805CVE-2026-20952CVE-2026-20953+6 CVEs160
ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, BillionThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Vulnerability55
LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware AttacksThe Hacker News·Dec 7, 07:08 UTC · Dec 7, 2023Vulnerability30
Microsoft Patch Tuesday, May 2023 EditionKrebs on Security·May 10, 07:06 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-24941+2 CVEs60
End of 2021 witnessed an explosion of RDP brute-force attacksHelp Net Security·Feb 9, 00:00 UTC · Feb 9, 2022VulnerabilityCVE-2017-1188247
Eleven Vulnerable UEFI Shims Enable Secure Boot BypassInfosecurity Magazine·Jul 15, 14:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-10797135
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Vulnerability landscape analysis for Q2 2025Kaspersky Securelist·Aug 27, 10:00 UTC · Aug 27, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Friday Squid Blogging: Squid Run in Southern New EnglandSchneier on Security·Jun 6, 21:00 UTC · Jun 6, 2025Vulnerability30
New UEFI Secure Boot bypass vulnerability discovered (CVE-2024-7344)Help Net Security·Jan 16, 00:00 UTC · Jan 16, 2025VulnerabilityCVE-2024-734435
Microsoft patches Windows to eliminate Secure Boot bypass threatArs Technica · Security·Jan 15, 00:00 UTC · Jan 15, 2025VulnerabilityCVE-2024-7344135
"Perfect" Windows downgrade attack turns fixed vulnerabilities into zero-daysHelp Net Security·Aug 30, 12:36 UTC · Aug 30, 2024VulnerabilityCVE-2024-38202CVE-2024-2130260
Sonos Speaker Flaws Could Have Let Remote Hackers Eavesdrop on UsersThe Hacker News·Aug 10, 07:14 UTC · Aug 10, 2024VulnerabilityCVE-2023-50809CVE-2023-50810CVE-2024-2001860
Some good may come out of the CrowdStrike outageHelp Net Security·Jul 29, 00:00 UTC · Jul 29, 2024Vulnerability30
Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUsThe Hacker News·Jun 22, 05:43 UTC · Jun 22, 2024VulnerabilityCVE-2024-076247
April’s Patch Tuesday Brings Record Number of FixesKrebs on Security·Apr 9, 20:55 UTC · Apr 9, 2024Vulnerability in the wildCVE-2024-20670CVE-2024-29063CVE-2024-29988+2 CVEs160