FindArticles FindArticles
  • News
  • Technology
  • Business
  • Entertainment
  • Science & Health
  • Knowledge Base
FindArticlesFindArticles
Font ResizerAa
Search
  • News
  • Technology
  • Business
  • Entertainment
  • Science & Health
  • Knowledge Base
Follow US
  • Contact Us
  • About Us
  • Write For Us
  • Privacy Policy
  • Terms of Service
FindArticles © 2025. All Rights Reserved.
FindArticles > News > Technology

Windows Issues Secure Boot Patch Against Bootkits

Gregory Zuckerman
Last updated: January 19, 2026 12:19 am
By Gregory Zuckerman
Technology
5 Min Read
SHARE

Microsoft’s latest Patch Tuesday delivers a must-install fix that refreshes expiring Secure Boot certificates on Windows devices, closing a window that bootkit malware could exploit to take control of a PC before the operating system even loads. If you do one update this week, make it this one.

Why This Patch Matters for Windows Security

Bootkits attack the earliest stage of your computer’s startup chain, gaining persistence below the operating system where many security tools can’t see them. Once embedded, they can subvert trusted bootloaders, mask malicious changes, and survive reinstalls. Security teams have been on alert since real-world bootkits like BlackLotus demonstrated reliable exploitation of UEFI boot processes; researchers at ESET confirmed in-the-wild deployments, while CISA and the Microsoft Security Response Center have warned repeatedly that pre-boot compromises are among the hardest to detect and remediate.

Table of Contents
  • Why This Patch Matters for Windows Security
  • What Microsoft Changed in This Secure Boot Certificate Update
  • Who Should Install This Secure Boot Certificate Refresh
  • How to Update and Verify Protection on Windows Devices
  • Extra Hardening Steps to Strengthen System Defenses
  • The Bottom Line on Microsoft’s Boot Security Update
A screenshot of the Windows 11 desktop with the Start menu open, displaying pinned apps, recommended files, and the user profile.

Secure Boot is the countermeasure: it checks cryptographic signatures on firmware and bootloaders, allowing only trusted components to run. But that trust depends on certificates and revocation lists that must be kept current. When those certificates age out, devices risk either refusing legitimate boot components or, worse, continuing to trust outdated ones that attackers can abuse.

What Microsoft Changed in This Secure Boot Certificate Update

The new cumulative updates—KB5074109 for Windows 11 and KB5073724 for Windows 10—refresh Secure Boot certificate trust so Windows devices continue to validate known-good bootloaders and reject revoked ones. Microsoft notes that the Secure Boot certificates used by most Windows devices are set to expire in mid-2026, and that without these updates Secure Boot–enabled systems could fail to boot securely or stop trusting new boot components. In Microsoft’s own advisory, the company cautions that devices without the update risk compromising both serviceability and security.

This isn’t the first time Secure Boot trust has needed a tune-up. Past incidents such as BootHole in GRUB2 required broad certificate and revocation updates to prevent tampered bootloaders from loading. The current refresh is preventive maintenance on that same trust chain—done now to avoid a scramble later.

Who Should Install This Secure Boot Certificate Refresh

Short answer: everyone running a supported version of Windows 10 or Windows 11. While Microsoft’s guidance often targets IT and security administrators managing fleets, the risk model applies equally to home users. Bootkits tend to show up first in targeted attacks, but once techniques mature they trickle down fast. Keeping Secure Boot’s certificates current ensures your system remains eligible for future security updates and continues to validate trusted bootloaders.

A screenshot of the Windows 11 desktop with the Start menu open, displaying pinned apps and recommended documents.

Organizations with compliance requirements, high-value endpoints, or devices exposed to travel and untrusted peripherals should treat this as a priority. Past campaigns like TrickBoot, a module associated with TrickBot, probed systems for vulnerable firmware settings—reminding defenders that pre-boot weakness is prized by adversaries.

How to Update and Verify Protection on Windows Devices

Open Settings, go to Windows Update, and check for updates. On Windows 11 look for KB5074109; on supported Windows 10 systems look for KB5073724. Install, restart, and let the update complete. If you manage devices centrally, ensure your update rings or WSUS policies are greenlighting these packages across the estate.

After installation, confirm that Secure Boot is enabled. Press Start, type “System Information,” and open it; under System Summary, find Secure Boot State. It should read On. If it’s Off and you have modern hardware, enable Secure Boot in UEFI firmware settings, typically under Security or Boot. Note that Secure Boot requires UEFI mode, not legacy BIOS, and turning it on may require disabling legacy or CSM boot options.

Extra Hardening Steps to Strengthen System Defenses

Keep firmware up to date using your OEM’s update utility or Windows Update for Business if your vendor participates in firmware delivery. Ensure BitLocker is enabled to protect data at rest, and consider virtualization-based security features that isolate critical processes from tampering. Finally, limit unsigned or untrusted boot-time drivers; driver signing enforcement and controlled device installation policies help reduce pre-boot risk.

The Bottom Line on Microsoft’s Boot Security Update

Bootkits thrive in the shadows before Windows loads, and Secure Boot is your flashlight. Microsoft’s latest updates renew that trust so your PC keeps booting safely and keeps receiving security fixes. Install the update today, verify Secure Boot is on, and stay ahead of attackers who would love to meet your machine before Windows does.

Gregory Zuckerman
ByGregory Zuckerman
Gregory Zuckerman is a veteran investigative journalist and financial writer with decades of experience covering global markets, investment strategies, and the business personalities shaping them. His writing blends deep reporting with narrative storytelling to uncover the hidden forces behind financial trends and innovations. Over the years, Gregory’s work has earned industry recognition for bringing clarity to complex financial topics, and he continues to focus on long-form journalism that explores hedge funds, private equity, and high-stakes investing.
Latest News
Calls Grow For Google Photos E Ink Frame
iOS Tops Android In New Mobile OS Rankings
AdGuard Deal Bundles VPN and Ad Blocker for $40
Google Paywalls Continued Conversation in Gemini Live
Exploring cream888 Slot Games: A Comprehensive Analysis of Themes and Features
Elegant Wedding Suits for the Modern Groom: Trends and Insights
Android Live Updates Win Praise As Adoption Stalls
Qi2 Charger With Cooling Fan Revives Wireless Charging
Presidents’ Day Essentials I Would Buy Now
What ETF Investors Need to Know: Trading, Pricing, and Liquidity Explained
Android XR Glasses Draw Interest Despite Gemini Backlash
Experts Share Valentine’s Situationship Survival Guide
FindArticles
  • Contact Us
  • About Us
  • Write For Us
  • Privacy Policy
  • Terms of Service
  • Corrections Policy
  • Diversity & Inclusion Statement
  • Diversity in Our Team
  • Editorial Guidelines
  • Feedback & Editorial Contact Policy
FindArticles © 2025. All Rights Reserved.