Cyber Security News

CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the National Security Agency (NSA), has issued new guidance urging enterprises to verify and manage UEFI Secure Boot configurations to counter bootkit threats.

Released in December 2025 as a Cybersecurity Information Sheet (CSI), the document addresses vulnerabilities like PKFail, BlackLotus, and BootHole that bypass boot-time protections. Enterprises neglecting these checks face heightened risks from persistent firmware malware.​

UEFI Secure Boot, introduced in 2006, enforces boot policies using certificates and hashes in four variables: Platform Key (PK), Key Exchange Key (KEK), allowed database (DB), and revocation database (DBX).

It prevents unsigned boot binaries, mitigating supply chain risks during the transition from expiring 2011 Microsoft certificates to 2023 versions. While default settings on most devices block unknown malware, misconfigurations often from test keys or disabled modes, expose systems.

Highlighted Vulnerabilities

PKFail involved devices shipped with untrusted test certificates, enabling Secure Boot bypasses. BlackLotus (CVE-2023-24932) exploited bootloader flaws to disable enforcement despite status indicators showing it was active.

BootHole flaws in GRUB allowed arbitrary execution via malformed configs, overwhelming DBX memory on older hardware. These incidents underscore the need for routine audits beyond TPM or BitLocker reliance.

Administrators should first confirm enforcement: Windows users run Confirm-SecureBootUEFI in PowerShell (True indicates active); Linux users use sudo mokutil –sb-state.

Export variables with Get-SecureBootUEFI or efi-readvar, then analyze using NSA’s GitHub tools for certs/hashes. Expected setups feature system vendor PK/KEK, Microsoft 2011/2023 CAs in DB, and DBX hashes no test keys or permissive modes.

ComponentExpected Configuration Improper Indicators
PKSystem vendor certificateAbsent or test keys
KEKVendor + Microsoft 2011/2023Missing Microsoft KEKs
DBMicrosoft CAs + vendorEmpty or misplaced certs
DBXRevocation hashesBoot hashes or duplicates

Restore via UEFI setup to factory defaults or apply firmware/OS updates delivering capsules. For enterprises, integrate checks into procurement testing and SCRM processes.

NSA advises customization over disabling for stricter controls, with tools on GitHub. The guidance stresses full auditing modes and avoiding the Compatibility Support Module (CSM).

This CSI equips IT teams to safeguard boot integrity amid evolving threats. Download the full PDF from official sources for commands and diagrams​.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago