Fetching from the wire…
Public story · 2026-07-16 · high
Enterprise compliance programs that treat Secure Boot as a hard gate have been trusting a check that's stayed open for about a decade.
Why now: It surfaced the same week as a record-size Patch Tuesday and an actively exploited Windows 0-day, per Ars Technica.
Microsoft never revoked a set of old bootloader shims, leaving Secure Boot bypassable for roughly its entire existence, per Ars Technica.
Secure Boot is the root of trust that measured boot and disk-encryption attestation chains depend on. Every enterprise compliance assumption built on that chain inherits the flaw.
Not some rare exploit chain. Ars Technica describes them as old, forgotten bootloaders Microsoft never pulled from the trusted list, which is what makes the bypass trivial, not theoretical.
The report didn't land on its own. It arrived the same week as a record-size Patch Tuesday and an actively exploited Windows 0-day, per Ars Technica.
Patching the specific shims Ars Technica names won't close this out. Microsoft's revocation process is what let known-bad bootloaders stay trusted for years, and that's the same process that has to catch the next batch.
Any compliance program that keys attestation off "Secure Boot is on" needs to check what's actually in the trusted bootloader list. Checking whether the setting is flipped isn't enough.
Each link below shares sources, entities, or timing with this story.
Microsoft released Copilot / Shared entities / Same source domain / What happened next
Linked by a graph relationship (Microsoft released Copilot); both cover Ars Technica, Microsoft; reported by the same outlet (arstechnica.com).
Windows Defender built by Microsoft / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Windows Defender built by Microsoft); both cover Ars Technica, Microsoft; reported by the same outlet (arstechnica.com).
Microsoft uses GitHub Copilot CLI / Shared entities / What happened next
Linked by a graph relationship (Microsoft uses GitHub Copilot CLI); both cover Microsoft, Windows; picks up the Microsoft thread on 2026-08-07.
Codex released Windows / Shared entities / What happened next
Linked by a graph relationship (Codex released Windows); both cover Microsoft, Windows; picks up the Microsoft thread on 2026-07-29.
Claude Code criticizes Windows / Shared entity: Microsoft / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code criticizes Windows); both cover Microsoft; overlapping topics (been, chain, microsoft).
Microsoft released Foundry / Shared entities / Earlier coverage
Linked by a graph relationship (Microsoft released Foundry); both cover Microsoft, Windows; earlier Microsoft coverage from 2026-06-08.
Claude Code criticizes Windows / Shared entities / Earlier coverage
Linked by a graph relationship (Claude Code criticizes Windows); both cover Microsoft, Windows; earlier Microsoft coverage from 2026-05-28.
Codex released Windows / Shared entities / Earlier coverage
Linked by a graph relationship (Codex released Windows); both cover Microsoft, Windows; earlier Microsoft coverage from 2026-05-23.