Secure Boot

AppWizard
May 30, 2026
Activision is offering a 10% pre-order loyalty discount for previous owners of the Call of Duty® franchise on the Modern Warfare® 4 Vault Edition. Pre-ordering any digital edition grants early access to the Open Beta and the Hunter Killer Operator Skin for use in Call of Duty®: Black Ops 7 and Call of Duty®: Warzone™. The Vault Edition includes Call of Duty®: Modern Warfare® 4, the Hostile Alliance Operator Pack, the Special Forces Operator Pack, a Signature Weapon Collection, a BlackCell (1 Season) with a Battle Pass and additional content, and a DMZ Deployment Bonus. The game is set during a full-scale invasion on the Korean Peninsula, featuring a narrative involving South Korean soldiers and Captain Price. Gameplay includes various combat scenarios, a multiplayer mode focused on grounded combat, and a DMZ mode where players make critical decisions. Modern Warfare® 4 will be available on Xbox Series X|S and PC, but not on Xbox One, and online multiplayer requires a Game Pass Essential subscription and specific PC security requirements.
Winsage
May 28, 2026
A Secure Boot certificate refresh is being deployed across supported Windows devices via Windows Update. The Secure Boot certificates from 2011 will begin to expire in June 2026, prompting Microsoft to introduce new 2023-dated certificates to maintain security. Most users will require minimal action if their PCs are updated, but older devices may face challenges. The current certificates include: - Microsoft Corporation KEK CA 2011: expires June 24, 2026 - Microsoft UEFI CA 2011: expires June 27, 2026 - Microsoft Windows Production PCA 2011: expires October 19, 2026 The new certificates will remain valid until 2038, with plans for post-quantum cryptography around 2030. While PCs using the 2011 certificates will continue to function, they will lose access to new security protections, making them vulnerable to emerging threats. A notable example of such a threat is the BlackLotus bootkit, which exploited vulnerabilities to bypass Secure Boot. Microsoft's rollout strategy involves a staged update process that typically takes around 48 hours and may require restarts. Users are advised to keep Windows updated and check their Secure Boot status. Known issues may arise for older PCs, systems that bypassed Windows 11 requirements, Legacy BIOS systems, and custom firmware configurations. IT teams managing devices should inventory their systems, monitor specific event IDs, test updates, and document devices that cannot be updated.
Winsage
May 28, 2026
Microsoft released a mandatory patch (KB5087537) for Windows Server 2016 to enhance cryptographic layers and address critical vulnerabilities. This update is essential for organizations using legacy workloads, as mainstream support ended in January 2022, but extended support continues until January 12, 2027. The patch aims to prepare systems for the expiration of Windows Secure Boot certificates in June 2026, which, if not updated, could compromise security and expose systems to malware. The update uses a phased deployment model and includes a new SecureBoot folder to assist IT professionals in managing certificate status. It also addresses various quality-of-life issues, including bugs affecting Remote Desktop Connection and authentication errors with Microsoft services. However, a significant issue arises when the host server name is exactly 15 characters long, causing failures in the domain controller discovery process and obstructing critical operations. This bug is linked to the historical 15-character limit of NetBIOS, which affects the Active Directory lookup mechanism. Microsoft has acknowledged the issue but has not provided a timeline for a fix, leaving administrators to either rename servers or uninstall the update. As the Secure Boot deadline approaches, IT departments must carefully assess their environments to avoid disruptions while ensuring security compliance.
Winsage
May 27, 2026
Microsoft will change Secure Boot certificates in June 2026, impacting Windows 11 PCs. If users do not update the certificates, their PCs may still function but will lack critical boot updates and malware blacklists, potentially compromising security. Without the new certificates, systems cannot run the latest Windows Boot Manager, making them vulnerable to bootkit malware and hindering future Windows feature updates. Older computers using BIOS are exempt from this issue. The new Secure Boot certificates are valid until 2038. Users can check their Secure Boot status in the Windows Security app; a green circle indicates readiness for the deadline.
Winsage
May 27, 2026
Users of Windows 11 versions 24H2 and 25H2 can install the preview update KB5089573, upgrading their systems to builds 26100.8524 and 26200.8524, respectively. Users on Windows 11 version 26H1 can install KB5089570, upgrading to build 28000.2179. The updates introduce new features such as shared audio support over Bluetooth LE, multi-app camera support, custom user folder naming during setup, and enhancements to Magnifier, Secure Boot, Task Manager, Windows Hello, and Windows Search. They also include performance improvements and increased reliability for sign-in and Lock screens.
Winsage
May 26, 2026
Microsoft will begin the expiration of Secure Boot certificates on most PCs in June, marking the end of a 15-year period of stability. This affects all PCs manufactured before 2023. Users will likely need to perform multiple restarts during the update process, which includes pushing data into firmware and loading a new bootloader. Ignoring the Secure Boot deadline in June 2026 may lead to significant security risks, as Microsoft will stop providing essential boot updates and malware blacklists. The Windows Security App has been updated to help users monitor these changes, and users should check for warnings indicating the status of Secure Boot. It is important for Windows 10 users to ensure they are enrolled in the Extended Security Updates (ESU) program to avoid vulnerabilities.
Winsage
May 26, 2026
Secure Boot is a security mechanism that authenticates firmware-based software through trusted certificates during the startup process of Windows, preventing unauthorized code execution. It is part of the UEFI firmware standard and was introduced in 2011 to allow only verified, signed code to run at startup. Microsoft first implemented Secure Boot certificates in 2011 as an optional feature in Windows 8, and it remained optional in Windows 10. However, it became a mandatory requirement with the launch of Windows 11 in 2021, indicating the widespread adoption of UEFI systems.
Winsage
May 24, 2026
Windows Secure Boot is a feature of the Unified Extensible Firmware Interface (UEFI) specification that enhances system security by ensuring only trusted software is loaded during the startup sequence. It verifies the digital signatures of boot components to protect against malicious software and unauthorized access. Key aspects include enhanced security by preventing untrusted code execution, compatibility with various hardware and software configurations, and user control over Secure Boot settings for customization.
Winsage
May 21, 2026
A segment of Windows 11 users has been unable to receive updates since February due to issues stemming from the January Preview Update, which caused download timeouts. This has resulted in missed security patches and critical updates related to Secure Boot certificates. Users may experience crashes during the update process, indicated by the error code 0x80010002. To check if affected, users can view their update history in Settings; if no updates have been installed since January and updates have not been paused, they are likely impacted. Microsoft is working on a fix linked to download timeout changes and firewall settings. A Known-Issue Rollback (KIR) can be executed to revert to a previous state before the problematic update, restoring normal functionality. This rollback is available for specific Windows 11 versions and Windows Server 2025.
Winsage
May 21, 2026
Users have observed a new folder named “SecureBoot” in the Windows system folder following the installation of Windows 11's May update (KB5089549). This update may cause installation issues for some devices and introduces a directory that contains example scripts for IT professionals to manage Secure Boot certificate updates. Windows Secure Boot certificates are set to expire next month, and outdated certificates will lead to loss of support starting in June, potentially compromising Secure Boot functionality. Microsoft is distributing new certificates through Windows Update. The SecureBoot folder does not require individual users to take action, and deleting it is discouraged as it may cause complications with future Windows updates.
Search