ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Web Emergency
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. UEFI Secure Boot Bypass: Why Old Shims Threat...
  • All articles
  • Categories
  • Tags
  • Statuses

UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers

The Silent Threat in Your Boot ChainWhen we think about server security, we often focus on firewalls, intrusion detection, and patching the operating...

The Silent Threat in Your Boot Chain

When we think about server security, we often focus on firewalls, intrusion detection, and patching the operating system. But what about the code that runs before your OS even loads? Recent research has uncovered a critical vulnerability in the UEFI Secure Boot mechanism that affects many Linux-based servers and workstations. Eleven old UEFI shim bootloaders, all signed by Microsoft, can be exploited to bypass Secure Boot on systems that still trust the Microsoft Corporation UEFI CA 2011 certificate.

Server rack with cracked padlock symbolizing UEFI Secure Boot bypass risk

This is not a theoretical risk. Attackers can use these vulnerable shims to execute malicious code before the operating system starts, making it easier to install persistent bootkits or compromise the kernel. For system administrators and hosting providers, understanding this threat and knowing how to mitigate it is essential.

How the Attack Works: A BYOVD for the Pre-Boot Phase

The technique is reminiscent of a Bring Your Own Vulnerable Driver (BYOVD) attack, but it happens before the OS loads. Instead of bringing a vulnerable driver, the attacker brings a vulnerable but properly signed bootloader. The key is that the firmware trusts the Microsoft certificate, so it accepts the shim as valid. The attacker then places this shim in the boot path, for example, by modifying the EFI partition or a bootable USB drive.

Once the shim is executed, it can load unsigned code, effectively bypassing Secure Boot. This allows the attacker to gain a foothold before security tools like EDRs even start. The impact is significant: persistence becomes easier, and detection becomes harder because most security monitoring begins after the OS boots.

The affected shims are versions 0.9 or earlier, and they are associated with various distributions and tools, including Red Hat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, openSUSE, and third-party utilities like baramundi Management Suite, WipeDrive, PC Doctor Service Center, and Abitti. The vulnerabilities are tracked as CVE-2026-8863 and CVE-2026-10797.

Why the Certificate Expiry Doesn't Save You

A common misconception is that the Microsoft UEFI CA 2011 certificate expires on June 27, 2026, and that this would automatically invalidate old binaries. That's not true. As long as the certificate remains in the firmware's database (DB) and the specific shim's hash is not in the forbidden list (DBX), the bootloader will still be trusted. Expiry only affects new signatures, not previously signed code.

Therefore, the only reliable mitigation is to revoke the vulnerable shims by updating the DBX list. Microsoft has already released revocations, but applying them requires careful planning.

Mitigation Steps: Protecting Your Infrastructure

For administrators, the challenge is to apply these revocations without breaking boot on existing systems. Here's a practical approach:

  • Update your boot components first: Before applying any DBX updates, ensure that shim, GRUB, and other boot chain components are updated to versions that include SBAT (Secure Boot Advanced Targeting) protections. This prevents older, vulnerable versions from being used even if they are present.
  • Test in a controlled environment: Deploy the DBX updates on a small, representative subset of your hardware first. Verify that systems still boot correctly and that the DBX list is updated as expected. Use tools like Check UEFISecureBootVariables on Windows or uefi dbx audit on Linux to confirm the status.
  • Inventory all boot media: Don't forget rescue disks, maintenance USBs, and other bootable media. If they contain old shims, they may become unusable after the revocation. Create updated versions or ensure they are not needed in an emergency.
  • Monitor for anomalies: After applying updates, watch for any systems that fail to boot or show signs of tampering. This could indicate that an attacker had already exploited the vulnerability.

Protecting Your Servers with a Centralized Security Approach

Managing boot security across multiple servers can be complex, but it's part of a broader security posture. For businesses in Spain, especially those in Catalonia with offices in Barcelona, Lleida, Tarragona, or Girona, ensuring that all servers are protected against such threats is crucial. A centralized security solution can help you monitor and manage vulnerabilities across your entire infrastructure.

At ALMC.es, we understand the challenges of server administration. Our Abuse Shield service is designed to centralize the protection of your servers, offering automatic blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed. While it doesn't directly handle UEFI boot security, it complements your defenses by mitigating threats at the network level, reducing the risk of an attacker gaining a foothold in the first place.

By combining proactive boot security updates with robust network protection, you can significantly reduce your exposure to sophisticated attacks. Remember, security is a layered process, and every layer counts.

Conclusion: Act Now to Secure Your Boot Chain

The discovery of these vulnerable shims serves as a reminder that security must extend beyond the operating system. For system administrators and hosting providers, the steps to mitigate this issue are clear: update your boot components, apply DBX revocations carefully, and test thoroughly. Ignoring this could leave your servers exposed to attacks that bypass traditional security measures.

If you need assistance with server security or want to learn more about how Abuse Shield can help protect your infrastructure, don't hesitate to reach out to our team. We're here to help you keep your systems safe.

Related

  • Hugging Face Breach: Why Data Pipelines Are the New Security Frontier
  • FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC
  • Critical WordPress Flaw 'wp2shell' Exploited: Act Now to Secure Your Servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

API Integrations & Microservices
Virtualization & Containers (Docker, Kubernetes)
Process Automation (Scripts and Bots)
Full Stack Web Development Laravel, Vue.js
Process Automation Scripts and Bots
Relacionados
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 54 minutes ago
  • Evilginx and Device Code Phishing: Lessons from a Misconfigured Server
    Cybersecurity · 54 minutes ago
  • NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets
    Cybersecurity · 54 minutes ago
  • RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
    Cybersecurity · 54 minutes ago
  • GhostLock CVE-2026-43499: Patch Your Linux Servers Now
    Cybersecurity · 54 minutes ago
  • Fastjson 1.x RCE: A Practical Guide for System Administrators
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Chronos
    Database
  • Apifox MCP Server
    Development
  • Convex
    Official 🌟 Oficial
  • Postman MCP Server
    Development
  • Contentful
    Cloud Service
  • AI Knowledge System
    Database
  • SAP OData MCP Server
    Database
  • Vectorize
    Search
  • Cloudflare Remote MCP Server
    Cloud Service
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar