
Microsoft's Ongoing Battle with Security Flaws: Latest Updates and Fixes.
Microsoft has released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit, which is the first-known real-world malware that can bypass Secure Boot protections. The new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. However, the update will be disabled by default for at least a few months after it's installed and will eventually render current Windows boot media unbootable. Microsoft will be rolling the update out in phases over the next few months to avoid rendering any users' systems unbootable.
