Forgotten bootloaders expose Secure Boot blind spot
This digest was compiled by AI from multiple sources — links to the originals are below.

Nearly a dozen revoked UEFI shim bootloaders stayed trusted for years, allowing attackers to bypass Secure Boot. The flaw highlights a systemic gap in revocation management across the industry.
The Vulnerability
Researchers identified 11 revoked UEFI shim bootloaders that remained trusted by major operating systems, including Windows and Linux distributions. These bootloaders, signed with valid certificates, provide a persistent bypass of Secure Boot protections. The issue stems from incomplete revocation lists and delayed updates across vendor ecosystems.
Industry Response
Microsoft and Linux vendors have begun updating revocation databases, but the process remains fragmented. The UEFI Forum's revocation mechanism relies on voluntary compliance, leaving gaps. Security firm Eclypsium, which disclosed the findings, noted that attackers could exploit these bootloaders to deploy bootkits like BlackLotus.
What's Next
Vendors are expected to release updated revocation lists in the coming weeks. It remains unclear whether the UEFI Forum will mandate faster revocation cycles to prevent similar blind spots.
1 source
Forgotten bootloaders expose Secure Boot blind spot



