11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

2026-07-14T13:24:15Zc1be3b3eabf56cc287fb7a64fb956debc99b8533139ae82efcd769e4cd42e14a
address-leakagebrowser-extensioncrypto-wallet-extensionscryptocurrency-theftevilginxextension-privacyforg365git-repo-exfiltrationgrok-buildinfostealermicrosoft-entraidmicrosoft-signed-shimmisconfigurationmodheadernpmnpm-malwareoauth-client-id-spoofingphaaSphishingsecure-bootsupply-chaintrackinguefiwallet-stealerxai-data-leakage

What happened

A batch of high-impact security stories: researchers found 11 old Microsoft-signed Linux UEFI shims that can be abused to bypass Secure Boot; Joomla iCagenda/Balbooa extension flaws (CVSS 10.0) were added to CISA's KEV catalog (CVE-2026-48939 reported); multiple supply-chain and registry incidents (compromised jscrambler@8.14.0 dropping a Rust infostealer, Injective Labs GitHub compromise pushing wallet-key-stealing npm packages, 148 malicious npm packages used as booby-trapped student proxies to create a browser DDoS botnet); browser-extension privacy and telemetry concerns (ModHeader removed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c1be3b3eabf56cc287fb7a64fb956debc99b8533139ae82efcd769e4cd42e14a
Enrichment time
2026-07-14T13:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.