CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Windows and Linux users: The deadline to update Secure Boot keys is near

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 433

As cited

Copy frozen at (site build).

vulnerabilities

Windows and Linux users: The deadline to update Secure Boot keys is near

Three Microsoft-signed certificates used in Secure Boot, the chain of trust mechanism that verifies firmware and software during system startup, will expire on June 24. These certificates are critical for preventing UEFI bootkits, which are firmware-based malware that loads before operating systems and can persist across OS reinstallations. Windows and Linux users need to update their systems to obtain new keys before the deadline to maintain boot security protections.

Why it matters: Organizations should prioritize updating Secure Boot keys before June 24 to prevent systems from potentially booting unsigned or malicious firmware after certificate expiration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Windows and Linux users: The deadline to update Secure Boot keys is near

Three Microsoft-signed certificates used in Secure Boot, the chain of trust mechanism that verifies firmware and software during system startup, will expire on June 24. These certificates are critical for preventing UEFI bootkits, which are firmware-based malware that loads before operating systems and can persist across OS reinstallations. Windows and Linux users need to update their systems to obtain new keys before the deadline to maintain boot security protections.

Why it matters: Organizations should prioritize updating Secure Boot keys before June 24 to prevent systems from potentially booting unsigned or malicious firmware after certificate expiration.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary