Microsoft and Linux users must update cryptographic keys by June 24 to maintain Secure Boot protections against firmware-based UEFI infections following the discovery of critical LogoFail vulnerabilities.
Key Points
- Three Microsoft-signed certificates used for Secure Boot verification are set to expire on June 24.
- Secure Boot prevents UEFI bootkits from loading malicious firmware before the operating system starts.
- The update replaces 2011-era cryptographic signatures with new 2023 versions to mitigate risks like the LogoFail vulnerability.
- Windows 10 and 11 users can verify their status via the Device Security settings menu.
- Linux distributors are currently releasing updated "shims" to bridge Secure Boot keys with their bootloaders.