READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Three Microsoft Secure Boot Certificates Expire June 24. Windows and Linux Users Need to Act.

Three Microsoft Secure Boot Certificates Expire June 24. Windows and Linux Users Need to Act.
On June 24, 2026, three Microsoft-signed certificates that underpin Secure Boot will expire, leaving unpatched Windows and Linux systems exposed to firmware-level malware that loads before any antivirus software can run. This is a concrete, dated deadline. Users and IT administrators who have not applied relevant firmware and OS updates need to do so before Tuesday.

What's Expiring and Why It Matters

Secure Boot is the chain of trust that verifies every piece of firmware and software loading during system startup. It checks digital signatures to confirm code originates from a trusted source — a motherboard manufacturer, for instance — before anything else runs.

Three Microsoft-signed certificates at the core of that system expire June 24, 2026, according to Wired. Once they expire, the cryptographic handshake that Secure Boot depends on breaks down for unpatched systems.

The threat here is what Secure Boot is designed to stop: UEFI bootkits.

What a UEFI Bootkit Actually Does

The UEFI (Unified Extensible Firmware Interface) replaced the old BIOS as the software that initializes hardware before your operating system loads. A bootkit that infects the UEFI runs before Windows, before Linux, before your endpoint protection software. It runs before almost everything.

That makes it extraordinarily hard to detect and remove. Reinstall your operating system? The bootkit survives. Wipe and reload? Same result. It can reinfect the OS repeatedly from firmware that standard security tools never see.

Once embedded, these bootkits typically deploy credential-stealing malware, backdoors, or persistent surveillance tools onto the OS above them.

This Threat Is Not Theoretical

The history here is worth knowing. Wired traces UEFI-targeting malware back through a clear progression.

Early bootkits in the 1980s targeted Apple II machines via floppy disks. Windows-specific bootkits emerged as research proofs-of-concept in the early 2000s, with BootRoot demonstrated at the Black Hat security conference in 2005 — likely the first public example.

The jump to UEFI-specific attacks followed. By 2013, a researcher had demonstrated a Windows UEFI bootkit named Dreamboat.

The first confirmed real-world UEFI attack came in 2018 with LoJax, created by the Kremlin-linked hacking group known variously as Sednit, Fancy Bear, and APT 28. LoJax was a weaponized version of legitimate anti-theft software called LoJack. A nation-state actor had taken commercially available software, repurposed it as persistent firmware malware, and deployed it in the wild.

Since LoJax, the category has grown. UEFI bootkits are no longer the domain of security researchers. They are an active tool of sophisticated threat actors.

The Fair Concern: Update Friction Is Real

The strongest pushback on deadlines like this is legitimate. Firmware updates break things. IT administrators at hospitals, manufacturers, and critical infrastructure operators have watched BIOS and UEFI updates cause boot failures, hardware incompatibilities, and production outages. The hesitation to push firmware updates in environments where downtime is costly is not ignorance. It's hard-won operational caution.

That concern is real. It does not change the math on what an expired Secure Boot certificate means for attack surface, but it does mean organizations need time and a tested rollback plan before applying firmware changes, not a last-minute scramble.

For those operators, the window to test and stage updates in a controlled environment has already passed. The deadline is Tuesday.

What Users and Administrators Should Do Now

For Windows users, Microsoft has issued updates addressing the certificate renewal. Apply pending Windows Updates immediately and check for firmware updates from your device manufacturer. Dell, HP, Lenovo, and others have released UEFI updates tied to this transition.

For Linux users, the path depends on your distribution. Major distributions including Ubuntu, Fedora, and RHEL have shipped relevant Secure Boot shim updates. Check your package manager and apply available updates. If your system dual-boots Windows and Linux, both sides need attention.

Systems running older hardware with UEFI firmware that manufacturers have stopped supporting may not receive updated certificates at all. Those machines face a harder problem. Secure Boot may need to be reconfigured manually, or the system may need to be treated as a higher-risk endpoint going forward.

The Unresolved Question

Wired's coverage is accurate on the technical facts. What remains an open question as of June 21 is how Microsoft plans to handle the post-expiration gap for systems that miss the update window. Specifically: will expired certificates trigger boot failures, silent Secure Boot degradation, or user-visible warnings? Microsoft's official guidance on behavior after June 24 for unpatched machines has not been clearly publicized, and that communication gap is itself a risk for users who don't know what to expect when Tuesday arrives.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredA Critical Deadline Is Approaching for Windows and Linux Security