Back Feeds.4Sysops Vulnerable UEFI shims allow attackers to bypass Secure Boot protections
Researchers have identified at least eleven vulnerable UEFI shim bootloaders that allow attackers to bypass Secure Boot on any system trusting the Microsoft third-party certificate authority. These shims, primarily version 0.9 or older, act as a bridge between firmware and the operating system but contain decade-old flaws that can be exploited to execute unsigned code. Because attackers can simply bring their own copy of a trusted but vulnerable binary to a target machine, the protection is undermined regardless of the installed operating system. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
