#PKfail
In case you missed it from #LABScon24: BINARLY’s @matrosov.bsky.social and @pagabuc.bsky.social reveal their research into a firmware supply-chain security issue that affected major device vendors and hundreds of models, PKfail.

📺 Watch the full video: s1.ai/PKfail
December 13, 2024 at 9:48 PM
📺 #LABScon 2024 Replay: @matrosov.bsky.social
and @pagabuc.bsky.social reveal their research into a firmware supply-chain security issue that affected major device vendors and hundreds of models, PKfail.

👉 Watch the full video: s1.ai/PKfail
December 4, 2024 at 5:36 PM
Let's see...

- AT&T Breach
- CrowdStrike Outage
- RegreSSHion
- Intel Decay
- PKfail Secure Boot bypass

Man, this year is not a good year for CyberSecurity.
July 26, 2024 at 9:40 PM
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり
https://gigazine.net/news/20240726-pkfail/
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり
セキュリティ企業・Binarlyの研究チームが、Acer、Dell、GIGABYTE、Intel、Supermicroが販売する200種類以上のデバイスでブート時に任意コード実行が可能になる脆弱(ぜいじゃく)性「PKfail」を報告しました。脆弱性の起因は、セキュアブートの基盤となるプラットフォームキーが2022年に漏えいしたことと指摘されています。
gigazine.net
July 26, 2024 at 5:00 AM
Key takeaways include:
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
LABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management
Binarly’s Alex Matrosov and Fabio Pagani present PKfail, a firmware supply-chain security issue affecting major device vendors and hundreds of device models.
s1.ai
December 4, 2024 at 5:36 PM
#SecureBoot is completely broken, scream the headlines. Why? Researchers found huge flaws in the way big brands manage the #crypto keys that keep your PC’s boot process trustworthy.

They’re calling it #PKfail. In #SBBlogwatch, we scramble to rotate our keys. At #TechstrongGroup​’s #SecurityBlvd
PKfail: 800+ Major PC Models have Insecure ‘Secure Boot’
Big BIOS bother: Hundreds of PC models from vendors such as HP, Lenovo, Dell, Intel, Acer and Gigabyte shipped with useless boot protection—using private keys that aren’t private.
securityboulevard.com
July 26, 2024 at 5:21 PM
PKfail Secure Boot bypass lets attackers install UEFI malware
PKfail Secure Boot bypass lets attackers install UEFI malware
Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows attackers to bypass Secure Boot and install malware.
www.bleepingcomputer.com
July 25, 2024 at 9:52 PM
PKfail: The Massive Security Flaw Affecting Millions of PCs
by @beng3.bsky.social
See what Steve Gibson has to say about the latest security news.
PKfail: The Massive Security Flaw Affecting Millions of PCs | TWiT.TV
See what Steve Gibson has to say about the latest security news.
twit.tv
August 2, 2024 at 4:25 PM
Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue
Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue
Several vendors for consumer and enterprise PCs share a compromised crypto key that should never have been on the devices in the first place.
www.darkreading.com
July 26, 2024 at 9:28 PM
Key takeaways include:
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
LABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management
Binarly’s Alex Matrosov and Fabio Pagani present PKfail, a firmware supply-chain security issue affecting major device vendors and hundreds of device models.
s1.ai
December 13, 2024 at 9:48 PM
"Based on our data, we found PKfail and non-production keys on medical devices, desktops, laptops, gaming consoles, enterprise servers, ATMs, POS terminals, and some weird places like voting machines." reads the new report by Binarly.

Written Sept 17th

www.bleepingcomputer.com/news/securit...
PKfail Secure Boot bypass remains a significant risk two months later
Roughly nine percent of tested firmware images use non-production cryptographic keys that are publicly known or leaked in data breaches, leaving many Secure Boot devices vulnerable to UEFI bootkit mal...
www.bleepingcomputer.com
November 29, 2024 at 10:03 PM
JTAG Hacking with a Raspberry Pi [3]

Hands-on Firmware Extraction, Exploration, and Emulation of an EV Charger [4]

PKfail: Untrusted Secure Boot Platform Keys in Production [5]
January 1, 2025 at 12:13 PM
Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue ⚠️
www.darkreading.com/endpoint-sec...
Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue
Several vendors for consumer and enterprise PCs share a compromised crypto key that should never have been on the devices in the first place.
www.darkreading.com
July 26, 2024 at 10:53 PM
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり - GIGAZINE
https://gigazine.net/news/20240726-pkfail/
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり - GIGAZINE
セキュリティ企業・Binarlyの研究チームが、Acer、Dell、GIGABYTE、Intel、Supermicroが販売する200種類以上のデバイスでブート時に任意コード実行が可能になる脆弱(ぜいじゃく)性「PKfail」を報告しました。脆弱性の起因は、セキュアブートの基盤となるプラットフォームキーが2022年に漏えいしたことと指摘されています。
gigazine.net
July 26, 2024 at 2:27 PM
過去10年間に遡りUEFIファームウェアの影響がある主なデバイスベンダーには、Lenovo、Dell、HP、HPE、Supermicro、Intel、MSI、Gigabyteなどが含まれています。
対策:デバイスベンダーによるPKfail脆弱性に対処するセキュリティパッチを適用する
対象のデバイスリスト👉 22222483.fs1.hubspotusercontent-na1.net/hubfs/222224...
July 26, 2024 at 11:40 PM
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり
https://gigazine.net/news/20240726-pkfail/
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり
セキュリティ企業・Binarlyの研究チームが、Acer、Dell、GIGABYTE、Intel、Supermicroが販売する200種類以上のデバイスでブート時に任意コード実行が可能になる脆弱(ぜいじゃく)性「PKfail」を報告しました。脆弱性の起因は、セキュアブートの基盤となるプラットフォームキーが2022年に漏えいしたことと指摘されています。
gigazine.net
July 26, 2024 at 9:32 AM
コメントありがとうございます。例えばAMD Ryzenモデル(alienware-aurora-r15-amd-desktopなど)もPKfail問題の影響を受けています。これは、セキュアブートのPlatform Key(PK)が信頼されていない場合、攻撃者が改ざんされたファームウェアイメージに署名してセキュアブートの検証を通過させることができるためです。他のベンダーと同様に、UEFIファームウェアの一部でNon-Production暗号鍵が使用されていることが確認されています。
July 29, 2024 at 3:28 PM
>American MegatrendsというBIOSベンダーが生成したテスト用のプラットフォームキーが、OEMやデバイスベンダーによって共有されてそのまま流用されていることが問題だとしています。

暗号関係になると途端に理解する事を放棄してお粗末な仕事をするエンジニアが結構多いと思うのだけど、有名メーカーでも大差無いのかな……
簡単だとは言わないけど、腰を落ち着けて取り組めば出来ないエンジニアは居ないと思ってる。
gigazine.net/news/2024072...
Acer・Dell・GIGABYTE・Intel・Supermicroの数百以上のデバイスでUEFIセキュアブートのプラットフォームキーが漏えいしていたと発覚、システム侵害のリスクあり
セキュリティ企業・Binarlyの研究チームが、Acer、Dell、GIGABYTE、Intel、Supermicroが販売する200種類以上のデバイスでブート時に任意コード実行が可能になる脆弱(ぜいじゃく)性「PKfail」を報告しました。脆弱性の起因は、セキュアブートの基盤となるプラットフォームキーが2022年に漏えいしたことと指摘されています。
gigazine.net
July 26, 2024 at 9:38 AM
Binarly reads the firmware layer no one else looks at - and keeps finding things vendors shipped by accident.

https://yespress.io/binarly?utm_source=bluesky&utm_medium=social via Yespress
Binarly - Reading the Code Below the Operating System
The firmware security company that turned an industry blind spot into a business - and disclosed the 12-year PKfail flaw.
yespress.io
August 7, 2026 at 6:07 PM
Dude, Bruno Guimarães? Why didn't Vini Jr. take the PK? Stop with the stutter step. #worldcup2026 #Roundof16 #BRAvsNOR #blewit #PKfail
July 5, 2026 at 8:23 PM