Skip to main content
Secure Boot

Secure Boot

Search complete. 130 mentions across 19 episodes found for "Secure Boot".

Sep 11, 2026

Tom WestcottHOST
16:31
You would then be in a position to relatively easily correct that vulnerability when it's discovered, if it's discovered to be a problem in the field.
Tom WestcottHOST
16:42
So how, if I have a fleet of devices, so I've used the Secure Boot tools that we provide to be able to do that.
Tom WestcottHOST
16:52
How could we then interact with the devices in the field? What could we do to audit what we have? How do we audit our fleet? How do we then distribute updates to the fleet when we need to or should we need to in the case of
Matthew LearGUEST
17:10
vulnerability? So we're talking about two, I guess, two discrete pieces of software.
Jerry BellHOST
1:28
Upgrade the agent and until then restrict who can start a remote host port forwarding session, the deny list was just checking spelling, not addresses.
Jerry BellHOST
1:37
Five, a kernel driver shipping in the AO MEI back-upper lets any local user write straight to the physical disk with secure boot off that becomes code at UEFI level before the operating system loads underneath HVCI, EDR and Defender and possibly reaches BitLocker keys.
Jerry BellHOST
1:56
There's no fix yet.
Jerry BellHOST
1:57
Block that driver and confirm secure boot is on.
Jerry BellHOST
2:01
Six, Anthropic disrupted a Russian operation that used Claude to watch whether its malware was being detected.
Jerry BellHOST
2:07
And when a tool got flagged, agents rebuilt and redeployed it until it wasn't.
Paul AsadoorianHOST
10:21
Um, and you know, these are super important.
Paul AsadoorianHOST
10:25
It talks about early DMA exposure, um, from incomplete IO, MMU, secure boot key problems, all of those issues that I've talked about on the show before, like they just keep adding up.
Paul AsadoorianHOST
10:39
They just keep coming.
Paul AsadoorianHOST
10:40
All these components that sit below your operating system have vulnerabilities.
Paul AsadoorianHOST
10:54
Occasionally going after these areas, and I think that we will continue to see malware exploit this attack surface.
Paul AsadoorianHOST
11:03
In fact, a more recent strain of malware that I found this week called Sheet Rat.
Paul AsadoorianHOST
11:10
attacks the secure boot and bootloader pre-operating system layer in that malware.
Paul AsadoorianHOST
11:17
Yeah, no sheet, huh? So I think as attackers look for better places to hide and persist, these are the areas in which they will do so when other avenues hopefully start to dry up in the OS layer.
Paul AsadoorianHOST
10:04
Recent Intel related UEFI microcode, SMM, TDX, and all of those early boot issues have been there's like another round of patching as well as another vulnerability that was discovered by my coworker that I'll roll into this story as well.
Paul AsadoorianHOST
10:21
um and you know these are super important it talks about early dma exposure um from incomplete io mmu secure boot key problems all of those issues that i've talked about on the show before like they just keep adding up like they just keep coming all these uh components that sit below your operating system have vulnerabilities now I will say that I don't see...
Paul AsadoorianHOST
10:49
Well, in this case, I do see malware and threat actors occasionally going after these areas.
Paul AsadoorianHOST
10:56
And I think that we will continue to see malware exploit this attack surface.
Paul AsadoorianHOST
11:03
In fact, a recent strain of malware that I found this week called SheetRat attacks the secure boot and bootloader pre-operating system layer in that malware.
Paul AsadoorianHOST
11:17
Yeah, no sheet, huh? So I think as attackers look for better places to hide and persist...
Paul AsadoorianHOST
11:24
These are the areas in which they will do so when other avenues hopefully start to dry up in the OS layer.
Paul AsadoorianHOST
14:19
How's that to prime the pump? uh yeah we're not telling dad jokes now so say that and then say you can't tell a dad joke
Paul AsadoorianHOST
10:21
Um, and you know, these are super important.
Paul AsadoorianHOST
10:25
It talks about early DMA exposure, um, from incomplete IO, MMU, secure boot key problems, all of those issues that I've talked about on the show before, like they just keep adding up.
Paul AsadoorianHOST
10:39
They just keep coming.
Paul AsadoorianHOST
10:40
All these components that sit below your operating system have vulnerabilities.
Paul AsadoorianHOST
10:54
Occasionally going after these areas, and I think that we will continue to see malware exploit this attack surface.
Paul AsadoorianHOST
11:03
In fact, a more recent strain of malware that I found this week called Sheet Rat.
Paul AsadoorianHOST
11:10
attacks the secure boot and bootloader pre-operating system layer in that malware.
Paul AsadoorianHOST
11:17
Yeah, no sheet, huh? So I think as attackers look for better places to hide and persist, these are the areas in which they will do so when other avenues hopefully start to dry up in the OS layer.
Paul AsadoorianHOST
10:04
Recent Intel related UEFI microcode, SMM, TDX, and all of those early boot issues have been there's like another round of patching as well as another vulnerability that was discovered by my coworker that I'll roll into this story as well.
Paul AsadoorianHOST
10:21
um and you know these are super important it talks about early dma exposure um from incomplete io mmu secure boot key problems all of those issues that i've talked about on the show before like they just keep adding up like they just keep coming all these uh components that sit below your operating system have vulnerabilities now I will say that I don't see...
Paul AsadoorianHOST
10:49
Well, in this case, I do see malware and threat actors occasionally going after these areas.
Paul AsadoorianHOST
10:56
And I think that we will continue to see malware exploit this attack surface.
Paul AsadoorianHOST
11:03
In fact, a recent strain of malware that I found this week called SheetRat attacks the secure boot and bootloader pre-operating system layer in that malware.
Paul AsadoorianHOST
11:17
Yeah, no sheet, huh? So I think as attackers look for better places to hide and persist...
Paul AsadoorianHOST
11:24
These are the areas in which they will do so when other avenues hopefully start to dry up in the OS layer.
Paul AsadoorianHOST
14:19
How's that to prime the pump? uh yeah we're not telling dad jokes now so say that and then say you can't tell a dad joke
JeremyHOST
0:46
Plus, Windows 11 24H2 is getting closer to its end of support.
JeremyHOST
0:50
Microsoft is making some important changes behind the scenes with Secure Boot, and we need to talk about why Windows 11 26H1 probably isn't the update that you think it is.
JeremyHOST
1:00
We'll also check out a tool that can turn one USB drive into an entire repair toolkit.
JeremyHOST
1:06
And later, from the office desk, we're talking about something that can save you a ton of troubleshooting time before a computer even reaches your workbench, a better repair intake process.
JeremyHOST
3:54
Just go ahead and add that Windows version check to that list.
JeremyHOST
3:58
It takes 10 seconds and it can prevent you from handing the customer back a computer that's about to fall out of support.
JeremyHOST
4:06
Next up, Microsoft is continuing a pretty important behind-the-scenes change involving Secure Boot.
JeremyHOST
4:12
Secure Boot certificates originally issued back in 2011 have started reaching their expiration period in 2026.
Jerry BellHOST
0:40
Push the Chrome update today and force the restart.
Jerry BellHOST
0:43
Three, an implant on F5 BIG-IP APM appliances hook Apache and injects a web shell into a copy of the page held in memory, so the file on disk stays exactly as F5 shipped it.
Jerry BellHOST
0:56
Comparing those files against known good copies comes back clean, and that's the check most people would run.
Jerry BellHOST
1:02
Patch the appliance and then hunt in memory rather than on disk.
Jerry BellHOST
4:13
Turn off ADB over TCP on your managed Android fleet.
Jerry BellHOST
4:17
Fifteen.
Jerry BellHOST
4:18
Where the UEFI shell ships inside Flash, an administrator who can change the boot order can start it and use its memory write commands to turn off the checks secure boot relies on.
Jerry BellHOST
4:30
Cisco has firmware updates out for UCS, and set a BIOS password while you're in there.
Steve GibsonHOST
27:30
Um, s- but okay, so here's what, what's actually gonna change.
Steve GibsonHOST
27:35
Memory integrity has always been enabled by default for clean Win 11 installs and so-called secured-core PCs, like, you know, that, that, that ship with Secure Boot, uh, enabled.
Steve GibsonHOST
27:53
Uh, and that's been true ever since the Device Guard days.
Steve GibsonHOST
27:58
And that's why, because it shipped enabled, gamers were frequently turning that off and seeing a performance boost.
Will SmithHOST
63:59
He has done very extensive documentation about how just kind of the boot chain works from the time you turn your computer on to how UEFI takes over and what it can boot and where partitions need to live and all that stuff is kind of the place to start with that stuff and then i think he'll probably link off to maybe some other stuff from his documentation here and there when i'm looking at
Brad ShoemakerHOST
64:21
the refine page he still does blue links for stuff you haven't read and purple links for stuff you have clicked and like the getting refined installing and uninstalling refined using refine configuring the boot manager using efi drivers and managing secure boot all purple links on my those are some of his blog posts that i've read
Will SmithHOST
64:39
Yes.
Will SmithHOST
64:39
Yes.

9 more episodes mention Secure Boot.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.