Microsoft issued a Secure Boot playbook telling organizations to update Windows and firmware trust chains before older Secure Boot certificates begin expiring in June 2026. The guidance says Secure Boot relies on CA-backed keys in UEFI firmware to validate trusted boot components and reduce exposure to early-boot malware, and ties the certificate refresh to protections against the BlackLotus bootkit issue tracked as CVE-2023-24932. Microsoft said many PCs built since 2024 already include the newer 2023 certificates, while other systems may need monthly Windows updates, OEM BIOS/UEFI updates, or both. The company recommended a phased rollout that starts with device inventory and Secure Boot status checks, then pilots updates and validates success through registry keys and Windows Event Log indicators.
Enterprise administrators reported that Windows updates alone may not be sufficient on all hardware, particularly for Lenovo and other systems that still require vendor firmware updates to ensure compatibility and load the new certificates into UEFI defaults. Practitioners also warned that automatic certificate deployment can depend on factors such as firmware readiness, telemetry, and whether devices fall into Microsoft's higher-confidence rollout groups. Operational concerns raised include multiple reboot cycles, possible BitLocker impacts, scheduled task triggers, and the need to update related Secure Boot-dependent assets including servers, virtual machines, PXE images, and recovery media.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Windows IT Pro Blog post advising organizations to update Windows Secure Boot certificate authorities before older certificates begin expiring. The playbook describes deployment methods, validation steps, troubleshooting guidance, and the need for OEM firmware updates where required.
Microsoft stated that many Windows PCs manufactured since 2024 already include the updated 2023 Secure Boot certificates, reducing the need for later remediation on those devices.
Microsoft said the updated Secure Boot certificates are a security measure to address the BlackLotus UEFI bootkit vulnerability tracked as CVE-2023-24932.
Microsoft said older Secure Boot certificates begin expiring in June 2026 and urged organizations to install the 2023 certificate authorities before the 2011 CAs expire.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.