
tutorials · 10 min
PKfail: Secure Boot keys leaked and shipped in production for 12 years
On 25 July, Binarly publishes the result of auditing the firmware of ~900 devices: hundreds use AMI/Insyde test keys with the string "DO NOT TRUST" in the subject, and the private half is on GitHub. CVE-2024-8105, VU#455367, Secure Boot bypass by design.
· Manuel López Pérez










