
New from Eclypsium: CVE-2026-25250. A Microsoft-signed third-party bootloader that completely skips signature verification when loading drivers. Secure Boot bypass on most Windows systems. Discovered by Mickey Shkatov and Stas Lyakhov. Patch now. https://hubs.ly/Q04crLzN0 https://t.co/FhYKdMNdxJ
Post summary
The tweet highlights CVE-2026-25250, a Secure Boot bypass involving a signed bootloader that skips signature verification, and notes that a patch is now available.

