TrendKia
AllNational
World
All World
PakistanChinaAmericaEuropeAsia
Politics
Business
All Business
MarketMoneyAutoBenefitsSuccess StoriesCryptoAI
Uttar Pradesh
Uttar Pradesh
Uttar PradeshBiharMadhya PradeshRajasthanDelhiMaharashtraGujaratPunjabHaryanaWest BengalTamil NaduKeralaKarnatakaTelanganaAndhra PradeshJharkhandChhattisgarhOdishaAssamUttarakhandHimachal PradeshJammu & KashmirGoaChandigarhPuducherry
Travel
Travel
Sports
CricketTennisFootball
EntertainmentMovies, TV & celebrities
BollywoodOTTBhojpuriMovie ReviewsTVHollywood
TechnologyGadgets, apps & innovation
AccessoriesLaunch & ReviewDIY
HealthHealth, fitness & wellness
LifestyleFashion, relationships & lifestyle
Fashion & BeautyCultureRelationshipsTrendsParenting
FoodRecipes, food & restaurants
ReligionFaith, belief & spirituality
FestivalsVastuSpirituality
TravelDestinations & travel guides
Travel Tips
EducationJobs, exams & results
VacanciesAdmissionExamResultsCareer
National
World
Pakistan China America Europe Asia
Politics
Business
Market Money Auto Benefits Success Stories Crypto AI
Sports
Cricket Tennis Football
Entertainment
Bollywood OTT Bhojpuri Movie Reviews TV Hollywood
Technology
Accessories Launch & Review DIY
Health
Lifestyle
Fashion & Beauty Culture Relationships Trends Parenting
Food
Religion
Festivals Vastu Spirituality
Travel
Travel Tips
Education
Vacancies Admission Exam Results Career
Uttar Pradesh Bihar Madhya Pradesh Rajasthan Delhi Maharashtra Gujarat Punjab Haryana West Bengal Tamil Nadu Kerala Karnataka Telangana Andhra Pradesh Jharkhand Chhattisgarh Odisha Assam Uttarakhand Himachal Pradesh Jammu & Kashmir Goa Chandigarh Puducherry
About Contact Privacy Cookies Terms Advertise
TrendKia logo हिंदी • English न्यूज़ प्लेटफ़ॉर्म

TrendKia

तेज़ • ताज़ा • हमेशा ट्रेंड पर

TrendKia is a free bilingual Hindi–English news platform — trending stories from India and around the world. Sign in with Google to comment, follow topics and earn reward points.

भारत और दुनिया की ताज़ा ट्रेंडिंग ख़बरें, हिंदी और अंग्रेज़ी में।

हमारे बारे में
TrendKia news app preview
TrendKia
AboutContactPrivacyCookiesTermsAdvertise
Why June 24 Is a Crucial Deadline for Windows and Linux Systems: Secure Boot Certificates Are ExpiringSecurity
5 hours ago· 2

Why June 24 Is a Crucial Deadline for Windows and Linux Systems: Secure Boot Certificates Are Expiring

Three critical Microsoft-signed Secure Boot certificates are set to expire on June 24, forcing a major cryptographic update across Windows and Linux devices globally.

RavikashRavikashSenior Correspondent 4 min read For AI
Share

An Impending Security Deadline on June 24

A major cryptographic shift is quietly taking place in the world of computer security. On June 24, three vital digital certificates signed by Microsoft are scheduled to expire. These certificates serve as the cornerstone of Secure Boot, an essential security mechanism designed by Microsoft to establish a chain of trust when a computer starts up. Secure Boot operates by validating the cryptographic signatures of all software and firmware that load during the boot process, confirming they come from trusted sources like the motherboard's manufacturer.

The primary purpose of Secure Boot is to defend against UEFI bootkits. This dangerous category of malware targets the Unified Extensible Firmware Interface (the modern successor to the traditional BIOS) which initiates the computer's startup sequence. Since bootkits execute before the operating system (OS) and security software even load, detecting them is notoriously difficult. Once active, bootkits can inject malware into the OS to steal credentials, open backdoors, or run malicious code. A bootkit remains highly resilient, often surviving complete OS reinstallations and manual disinfection attempts.

The History and Evolution of Bootkits

The history of boot-level malware stretches back to the early 1980s. The earliest variants targeted Apple II computers, spreading through floppy disks that appeared to hold pirated video games. By the early 2000s, offensive security researchers began developing proof-of-concept (PoC) bootkits targeting Windows systems. The first notable example, BootRoot, was presented at the 2005 Black Hat security conference. It compromised the Network Driver Interface, which manages communications for network protocol drivers like TCP/IP. This was followed by other research PoCs like Vbootkit, Stoned Bootkit, and Mebroot.

In 2012, researchers demonstrated new techniques. One malware attacked Mac OS X by targeting the EFI firmware. Another early exploit targeted Windows 8 machines by compromising the predecessor to UEFI. Around 2013, a more sophisticated UEFI-targeting bootkit for Windows, named Dreamboat, was showcased by researchers.

The threat moved from theory to reality in 2018 when the first real-world UEFI malware, LoJax, was discovered. Based on a repurposed anti-theft software called LoJack, it was deployed by the Kremlin-linked threat group known as Sednit, Fancy Bear, or APT 28. Attackers installed LoJax remotely using tools capable of overwriting the UEFI firmware's flash memory.

By 2020, researchers at Kaspersky identified the second known in-the-wild UEFI threat, named MosaicRegressor. Upon system reboot, this malware checked the Windows startup folder and silently reinstalled malicious files if they were missing. While researchers could not confirm exactly how the UEFI was compromised initially, several other UEFI bootkits have emerged since, including ESpecter, FinSpy, and MoonBounce.

The LogoFail Vulnerability and the Key Rotation

According to reporting by TrendKia, the urgent need for a certificate replacement became clear in 2023 with the discovery of LogoFail. This massive vulnerability affected the UEFI of almost all Windows and Linux devices globally. It exploited a bug in the image-parsing software that displays computer manufacturer logos during bootup. By manipulating these images, hackers could bypass Secure Boot entirely and infect the firmware.

To patch LogoFail, Microsoft has been forced to deprecate three older Secure Boot cryptographic signatures dating back to 2011. They are being replaced by modern signatures dated 2023. Microsoft is currently pushing these updates to Windows 10 and Windows 11 systems. Meanwhile, Linux distributions are rolling out updates for their "shims", which are small, early-stage bootloaders acting as a secure bridge between Secure Boot and the Linux system.

Systems that do not receive these key updates will continue to work, but they will remain defenseless against modern UEFI threats. TrendKia notes that these unpatched machines are already exposed to LogoFail. This key update is vital to close that loophole and guard against future firmware-level attacks.

How to Verify and Update Your Device

Windows users can verify if their system has been updated by opening Windows Security, navigating to Device Security, and checking the Secure Boot status. A green checkmark confirms that the updates are successfully applied. While most modern computers receive these updates automatically through monthly Windows Update patches, older devices might require manual intervention. For Linux users, keeping an eye out for the latest shim releases from their distribution is recommended.

Microsoft advises users to keep all device firmware up to date, as these updates are often necessary for the Secure Boot certificates to update seamlessly.

What this means for you

  • For Computer Users: Ensuring your Windows or Linux system is updated before June 24 is vital to stay protected against hidden bootkit malware that cannot be detected by standard antivirus software.
  • For IT Professionals: Legacy systems and older hardware may require manual firmware updates to properly accept the new 2023 cryptographic keys, making a manual audit necessary.

Questions & Answers

What is happening regarding security on June 24?
On June 24, three legacy Microsoft-signed Secure Boot cryptographic certificates dating back to 2011 are set to expire, requiring system updates.
What is the function of Secure Boot?
It is a startup-level security system that validates the digital signatures of all loaded firmware and software to ensure they come from trusted hardware manufacturers.
Will my PC stop working if I fail to update the Secure Boot keys?
No, your PC will continue to boot and run normally, but it will remain vulnerable to LogoFail and other advanced firmware-level security threats.
What is the LogoFail vulnerability?
Discovered in 2023, LogoFail is a critical bug in the image-parsing software of system firmware that allows hackers to bypass Secure Boot via the manufacturer boot logo.
How can I verify if my Windows system is already updated?
Navigate to Windows Security settings, select Device Security, and check the Secure Boot status. A green checkmark indicates the cryptographic update is complete.
#Security#Microsoft#Windows Security#Linux#Secure Boot#Cybersecurity#LogoFail
TrendKia Rewards

Read the news, earn real rewards

Every article you read earns points — redeem for gifts up to ₹10,000. Free to join.

Register free & start earning
₹250Mobile Recharge
12,500 · ≈ 12,500 reads
Start earning
₹500Gift Voucher
25,000 · ≈ 25,000 reads
Start earning
₹1,000Gift Card
50,000 · ≈ 50,000 reads
Start earning
₹2,000Gift Card
1,00,000 · ≈ 1,00,000 reads
Start earning
₹3,000Shopping Voucher
1,50,000 · ≈ 1,50,000 reads
Start earning
₹5,000Cash / UPI
2,50,000 · ≈ 2,50,000 reads
Start earning
PREMIUM₹7,500Cash / UPI
3,75,000 · ≈ 3,75,000 reads
Start earning
PREMIUM₹10,000Cash / UPI
5,00,000 · ≈ 5,00,000 reads
Start earning
PREMIUM₹15,000Mega Cash
7,50,000 · ≈ 7,50,000 reads
Start earning

Comments 0

Sign in to join the conversation.

Sign in

No comments yet — be the first.

Market1
Wall Street's Big Bet on AMZN: Where Could Amazon Stock Land Between 2026 and 2028?
Politics2
Three Indian Sailors Killed in Gulf of Oman Strike: Shashi Tharoor Tears Into US Over 'Insensitive' Statement, Presses Jaishankar Too
Security3
FCC's 'Know Your Customer' Plan Could End Anonymous Phones — Plus the Week's Biggest Breaches and Busts

Latest news straight to your inbox

The day's big stories, in one email.

TrendKia बाज़ारAdvertisementमानसून सेल — हर चीज़ पर 50% तक छूटTrendKia बाज़ारअभी खरीदें →
Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
Citizen journalistCitizen journalist
Citizen journalist
Citizen journalist

Related stories

From Gaurang to Disco Dancer: How Mithun Chakraborty Kept His Crown Despite 33 Straight FlopsBollywood
From Gaurang to Disco Dancer: How Mithun Chakraborty Kept His Crown Despite 33 Straight Flops
6 days ago
Rajnath Singh Celebrates International Yoga Day at Eastern Air Command in Shillong, Urges Everyone to Embrace YogaLeaders Speak
Rajnath Singh Celebrates International Yoga Day at Eastern Air Command in Shillong, Urges Everyone to Embrace Yoga
12 hours ago
International Yoga Day: Malaika Arora at 52 and the 3 Yoga Practices That Keep Her Looking This GoodHealth
International Yoga Day: Malaika Arora at 52 and the 3 Yoga Practices That Keep Her Looking This Good
12 hours ago
How Americans Really Pay for a Roof: Renters Who Gave Up, Owners Who Are Stressed, and Families Doubling UpMoney
How Americans Really Pay for a Roof: Renters Who Gave Up, Owners Who Are Stressed, and Families Doubling Up
5 days ago
Disney Unveils First Trailer For Magical Coming-Of-Age Film 'Hexed' Starring Hailee Steinfeld And Rashida JonesHollywood
Disney Unveils First Trailer For Magical Coming-Of-Age Film 'Hexed' Starring Hailee Steinfeld And Rashida Jones
5 days ago
Shiba Inu vs. Dogecoin: Which Crypto Truly Possesses the Superior Ecosystem?Crypto
Shiba Inu vs. Dogecoin: Which Crypto Truly Possesses the Superior Ecosystem?
1 day ago
Iran and US Converge in Switzerland for Next Round of Talks as Trump Sets 60-Day Hormuz UltimatumWorld
Iran and US Converge in Switzerland for Next Round of Talks as Trump Sets 60-Day Hormuz Ultimatum
13 hours ago
When Sonam Kapoor Called Aishwarya Rai 'Aunty': The 2009 Beauty-Brand Row That Refuses to FadeBollywood
When Sonam Kapoor Called Aishwarya Rai 'Aunty': The 2009 Beauty-Brand Row That Refuses to Fade
6 days ago