
10 days
I am not a hacker, but what I gathered from the article is that this is due to shims with vulnerabilities being left as trusted instead of being revoked. If that’s the case, wouldn’t the hacker be using a modified version of a compromised shim? It shouldn’t have to be a shim that you actually use right? Or does the signed shim have to correspond to thr correct OS that signed it?
Are you me?