
Findings and evidence
ESET identifies 11 older signed UEFI shim bootloaders that weakened Secure Boot trust. The July research describes coordinated reporting and revocations included in Microsoft’s June 2026 update cycle.
Why it matters
A forensic record should distinguish the Secure Boot setting from the actual firmware trust and revocation state. Record firmware versions and update history before making claims about the integrity of the boot chain.
Scope and limits
The paper concerns particular legacy boot components and trust configurations. It does not establish that every machine with Secure Boot enabled is affected or already compromised.
Primary source
ESET Research: original publication. Source published 2026-07-14. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.