iTnews Asia
  • Home
  • News
  • Security

MSI Boot Guard keys leaked

MSI Boot Guard keys leaked

Supply chain attacks could follow.

By Richard Chirgwin on May 8, 2023 12:35PM

Hackers have released code signing keys stolen from PC maker MSI in an April break-in, following the company’s refusal to pay a ransom demand.

Early in April, MSI acknowledged an attack, which resulted in the theft of databases, some source code, and BIOS firmware.

At the time, MSI reminded customers to only download firmware or BIOS updates from its official website.

Late last week the attackers, who call themselves Money Message, began releasing data on the dark web, and on May 4, Alex Matrosov of supply chain security company Binarly said in a Twitter post his company had identified “a vast number of private keys that could affect numerous devices”.

Data released included firmware signing keys for 57 products, and Intel BootGuard boot policy manifest and key manifest keys for 166 products.

Binarly has posted the keys to Github, including a list of affected products.

Matrosov noted that Binarly only posted public keys in its Github repo, not the private keys taken by the hackers.

Anyone with the private keys leaked on the dark web can sign malicious BIOS and firmware for the target machines, making them appear as if they’re official versions.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
money message msi security

Related Articles

  • Malicious AI inputs are creating a new and critical security threat
  • Beware the pitfalls of using a ‘DIY security’ approach
  • AI transforms cyberattacks, but human trust remains the weakest link
  • How severe will ransomware attacks become in 2026?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Malicious AI inputs are creating a new and critical security threat

Malicious AI inputs are creating a new and critical security threat

Singapore issues advisory for FIs to mitigate quantum computing risks

Singapore issues advisory for FIs to mitigate quantum computing risks

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.