Below the Surface (Audio) - The Supply Chain Security Podcast

HybridPetya and UEFI Threats - BTS #60

13 snips
Sep 22, 2025
Dive into the intriguing world of cybersecurity, where Hybrid Petya's evolution poses new threats. UEFI vulnerabilities and the challenges of secure boot are dissected, alongside risks tied to Windows 10's end of life. The podcast shines a light on Cisco ASA device exposures and the alarming rise of supply chain attacks, such as NPM worms. Row Hammer attacks targeting DDR5 technology add to the complexity, emphasizing the need for enhanced visibility and robust security practices. Explore how shifting consumer trust is impacting software choices!
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

UEFI Attacks Are Becoming Commodity

  • Secure-boot bypass techniques are moving from advanced research into commodity ransomware toolkits.
  • That shift lowers the skill barrier and broadens attack surfaces for everyday attackers.
ADVICE

Maintain Secure Boot Revocations

  • Update secure-boot revocation lists and DBXs proactively before systems reach end-of-support.
  • Treat firmware and secure-boot maintenance as operational tasks, not optional updates.
ANECDOTE

UEFI Update Caused Hour-Long Lockup

  • Vlad described a recent UEFI firmware update that left his laptop locked on a black screen for an hour.
  • He recovered it through intensive troubleshooting, showing update risks even for skilled users.
Get the Snipd Podcast app to discover more snips from this episode
Get the app