Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
Critical U-Boot Bugs Undermine Secure Boot on Millions of DevicesSecurity Affairs·Jul 11, 17:45 UTC · Jul 11, 2026VulnerabilityCVE-2020-10648CVE-2021-2709760
Windows and Linux users: The deadline to update Secure Boot keys is nearArs Technica · Security·Jun 17, 11:15 UTC · Jun 17, 2026Vulnerability155
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.Ars Technica · Security·Jun 10, 19:00 UTC · Jun 10, 2025VulnerabilityCVE-2025-3052CVE-2025-4782760
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI MotherboardsThe Hacker News·Dec 20, 13:28 UTC · Dec 20, 2025VulnerabilityCVE-2025-14304CVE-2025-11901CVE-2025-14302+1 CVEs60
BlackLotus is first bootkit bypassing UEFI Secure Boot on Win 11Security Affairs·Mar 1, 20:57 UTC · Mar 1, 2023VulnerabilityCVE-2022-2189460
Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approachesHelp Net Security·Jun 19, 12:16 UTC · Jun 19, 2026Industry155
Widely used DNA sequencer still doesn’t enforce Secure BootArs Technica · Security·Jan 7, 14:00 UTC · Jan 7, 2025Vulnerability55
Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux DistrosThe Hacker News·Feb 8, 03:11 UTC · Feb 8, 2024VulnerabilityCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
Critical shim bug impacts every Linux boot loader signed in the past decadeSecurity Affairs·Feb 7, 14:46 UTC · Feb 7, 2024MalwareCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
ASRock, ASUS, GIGABYTE, MSI Boards vulnerable to preSecurity Affairs·Dec 19, 10:27 UTC · Dec 19, 2025VulnerabilityCVE-2025-11901CVE-2025-14302CVE-2025-14303+1 CVEs60
BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11The Hacker News·Jun 23, 08:42 UTC · Jun 23, 2023Malware in the wildCVE-2022-21894160
After latest Microsoft Win updates some PCs running Sophos AV not bootSecurity Affairs·May 21, 14:46 UTC · May 21, 2019Exploit / PoCCVE-2019-070860
Sonos Speaker Flaws Could Have Let Remote Hackers Eavesdrop on UsersThe Hacker News·Aug 10, 07:14 UTC · Aug 10, 2024VulnerabilityCVE-2023-50809CVE-2023-50810CVE-2024-2001860
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News·Jun 29, 14:42 UTC · Jun 29, 2026Malware in the wildCVE-2026-43503CVE-2026-12569CVE-2026-47729+19 CVEs60
Critical GRUB2 Bootloader Bug Affects Billions of Linux and Windows SystemsThe Hacker News·Jul 29, 19:50 UTC · Jul 29, 2020MalwareCVE-2020-1071360
XPAJ: Reversing a Windows x64 BootkitKaspersky Securelist·Jun 19, 18:16 UTC · Jun 19, 2012Ransomware60
Flaw in some Acer laptops can be used to bypass security featuresSecurity Affairs·Nov 28, 20:10 UTC · Nov 28, 2022VulnerabilityCVE-2022-402060
Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware ExploitsThe Hacker News·Jan 24, 12:47 UTC · Jan 24, 2025VulnerabilityCVE-2020-10713CVE-2022-24030CVE-2021-33627+5 CVEs60
New Flaw in Acer Laptops Could Let Attackers Disable Secure Boot ProtectionThe Hacker News·Nov 29, 16:39 UTC · Nov 29, 2022VulnerabilityCVE-2022-402060
New bug in PC booting process could take years to fix, researchers sayCyberScoop·Jul 29, 18:01 UTC · Jul 29, 2020Ransomware in the wild60
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Microsoft Patches 67 Vulnerabilities Including WEBDAV ZeroThe Hacker News·Jun 12, 15:47 UTC · Jun 12, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-47966CVE-2025-32713+3 CVEs160
April’s Patch Tuesday Brings Record Number of FixesKrebs on Security·Apr 9, 20:55 UTC · Apr 9, 2024Vulnerability in the wildCVE-2024-20670CVE-2024-29063CVE-2024-29988+2 CVEs160
BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
Unpatched Critical Flaws Disclosed in UThe Hacker News·Jun 6, 14:04 UTC · Jun 6, 2022VulnerabilityCVE-2022-30790CVE-2022-3055260
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege EscalationThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-33825CVE-2025-48804160
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
Linux Devs Rush to Patch Critical Vulnerability in ShimInfosecurity Magazine·Feb 8, 16:30 UTC · Feb 8, 2024VulnerabilityCVE-2023-4054760
Critical vulnerabilities in Siemens PLC devices could allow bypass of protected boot features (CVE-2022-38773)Help Net Security·Jan 12, 00:00 UTC · Jan 12, 2023VulnerabilityCVE-2022-3877360
A review of Azure Sphere vulnerabilities: Unsigned code execs, kernel bugs, escalation chains and firmware downgradesCisco Talos·Nov 22, 19:00 UTC · Nov 22, 2021Vulnerability55
Thrangrycat flaw could allow compromising millions of Cisco devicesSecurity Affairs·May 17, 14:11 UTC · May 17, 2019VulnerabilityCVE-2019-1649CVE-2019-186260
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableThe Hacker News·Jul 25, 12:54 UTC · Jul 25, 2026Vulnerability in the wildCVE-2026-1672360
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
British Airways, BBC and Boots impacted the by Zellis data breachSecurity Affairs·Jun 7, 18:12 UTC · Jun 7, 2023Data breach60