An industry-wide standard that safeguards Windows devices from firmware infections had a vulnerability for around seven months which may have allowed the bypassing of protection with a simple technique. Patched by Microsoft on Tuesday, the status of Linux systems remains unknown. The exploit permitted attackers with device access to run harmful firmware during bootup, thus infecting the device before any OS loading.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.