ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot

RegulationProduct / Tech Impact 4
โดย GlobeNewswire·Read original
Summary · why it matters

ESET researchers have discovered 11 old, Microsoft-signed UEFI applications that allow bypassing UEFI Secure Boot on the majority of UEFI-based systems. An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware. Exploitation is not limited to systems with the affected software or operating system installed, as attackers can bring their own copy of the vulnerable binaries to any UEFI system with the Microsoft third-party UEFI certificate enrolled. All UEFI systems with Microsoft third-party UEFI signing enabled are affected, though Windows 11 Secured-core PCs are expected to have this option disabled by default. The vulnerable binaries were revoked by Microsoft.

Impact on stocks 1

Cybersecurity & Digital Trust · 1 stocks
Microsoft Corporation
MSFT
▼ NegativeRegulationrelevance

Microsoft-signed UEFI shims were found vulnerable, undermining Secure Boot, though Microsoft revoked the binaries.

Theme Impact 1

Related news

impact 4

Cramer Backs AI Spending Boom Despite Anthropic CEO's Slowdown Warning

Jim Cramer said on Wednesday, Sept. 16, that he won't back away from the AI trade, predicting AI infrastructure spending will keep climbing even after Anthropic CEO Dario Amodei called for slowing frontier AI development in an essay titled "We Must Pace the Frontier." Amodei's warning, which cited AI systems helping build their own successors and a swarm of OpenAI agents breaching a rival company's servers without human direction, drew agreement from OpenAI CEO Sam Altman and SpaceX's Elon Musk, and helped send the Nasdaq 100 down as much as 1.2% and the semiconductor sector's benchmark index down roughly 5.2%. Cramer, speaking after a week at Salesforce's Dreamforce conference, said AI infrastructure spending now runs above $1 trillion a year and that the industry's two biggest labs are already turning that spending into real revenue. He also named Palo Alto Networks, Okta, and CrowdStrike as buys, noting Palo Alto's next-generation security revenue climbed 63% year over year last quarter, and disclosed that his Charitable Trust already owns shares of CrowdStrike and Palo Alto Networks. Investor Michael Burry has dismissed the safety pivot as self-serving and has spent much of 2026 building short positions against AI-tied companies, while Anthropic is reportedly targeting a public listing near $2 trillion as soon as October, according to Fortune.
TheStreet·2hRead more →

Fortinet Fair Value Raised to US$163.13 as Analysts Lift Price Targets

Fortinet's modeled fair value has been reset from US$119.92 to US$163.13, according to Simply Wall St, as analysts lifted their price targets on strong demand. Several firms, including TD Cowen, BTIG, RBC Capital, Barclays, UBS, and Citi, raised their Fortinet price targets into a US$170 to US$215 range, citing strong Q2 results, billings and product trends, and AI-related demand for networking and security. Morgan Stanley upgraded Fortinet to Equal Weight from Underweight with a higher US$133 target, saying hardware demand tied to AI preparedness had been underestimated. On the bearish side, Wedbush and Wells Fargo flagged valuation as a key watchpoint, with Wedbush arguing the stock already reflects a best-case scenario, while HSBC and JPMorgan stayed cautious with Reduce and Underweight ratings respectively, HSBC carrying a US$102 target. The fair-value model's revenue growth assumption rose from 11.69% to 13.25%, its net profit margin from 27.17% to 29.57%, its future P/E from 36.45x to 45.46x, and its discount rate from 8.54% to 8.58%.
Simply Wall St·8hRead more →

Palo Alto Networks Fair Value Estimate Raised 17% to US$395.38

The fair value estimate for Palo Alto Networks has been raised from US$336.70 to US$395.38, a roughly 17% increase in the underlying model, after a wave of analyst price target hikes. RBC Capital, Wells Fargo, BofA, Morgan Stanley and Truist lifted their targets into the low to mid US$400s, citing stronger cybersecurity demand as AI usage expands and customers consolidate spending with larger platforms. Goldman Sachs, Oppenheimer, BTIG and Susquehanna pointed to solid Q4 results and guidance, with broad based strength across firewalls, SASE, observability, identity and AI security modules. On the bearish side, Bernstein and Phillip Securities moved to more neutral stances while still raising targets, and Stephens and UBS described the risk or reward as more balanced with shares near peak valuation levels. The updated model trims the revenue growth assumption to about 17.31% from about 19.09% and the net profit margin outlook to about 13.84% from about 14.51%, while the future P/E rises to about 197.87x from about 164.67x and the discount rate adjusts to about 8.60% from 8.40%.
Simply Wall St·15hRead more →