{"id":52475,"date":"2023-06-23T14:29:05","date_gmt":"2023-06-23T14:29:05","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34747\/Microsofts-Bootkit-Patches-Offer-False-Sense-Of-Security-Against-BlackLotus-Threat-NSA-Says.html"},"modified":"2023-06-23T14:29:05","modified_gmt":"2023-06-23T14:29:05","slug":"microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/","title":{"rendered":"Microsoft&#8217;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/black-lotus.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The National Security Agency (NSA) is urging organizations to harden their systems against <a href=\"https:\/\/www.scmagazine.com\/brief\/threat-intelligence\/novel-advanced-black-lotus-uefi-rootkit-examined\" target=\"_blank\" rel=\"noreferrer noopener\">BlackLotus UEFI bootkit malware<\/a>, warning there is \u201csignificant confusion\u201d and a \u201cfalse sense of security\u201d regarding the threat it poses.<\/p>\n<p>BlackLotus, first observed in October last year, has powerful features including the ability to disable Windows Defender, BitLocker, and Hypervisor-protected Code Integrity. The malware is also capable of infecting Windows machines with <a href=\"https:\/\/www.scmagazine.com\/brief\/malware\/windows-secure-boot-evaded-by-blacklotus-malware\" target=\"_blank\" rel=\"noreferrer noopener\">Secure Boot enabled<\/a>, exploiting a known vulnerability (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-21894\">CVE-2022-21894<\/a>) called Baton Drop.<\/p>\n<p>Microsoft addressed the additional Baton Drop vulnerability (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-24932\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-24932<\/a>) last month, issuing a fix as part of <a href=\"https:\/\/www.scmagazine.com\/brief\/vulnerability-management\/several-microsoft-vulnerabilities-addressed\" target=\"_blank\" rel=\"noreferrer noopener\">May\u2019s patch Tuesday<\/a>. But while the new patch provides configuration options to manually enable protections against the vulnerability, they are not enabled automatically. <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d\" target=\"_blank\" rel=\"noreferrer noopener\">According to Microsoft<\/a>, system administrators need to verify all their devices and bootable media are updated and ready for the patch before enabling the new protections.<\/p>\n<p>In a <a href=\"https:\/\/media.defense.gov\/2023\/Jun\/22\/2003245723\/-1\/-1\/0\/CSI_BlackLotus_Mitigation_Guide.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity information sheet<\/a> (PDF) released on Thursday, the NSA said the confusion over BlackLotus resulted in some organizations believing it was an unstoppable, unpatchable threat while others thought they were safe because they had applied the two patches Microsoft had issued.<\/p>\n<p>\u201cThe risk exists somewhere between both extremes,\u201d the information sheet said.<\/p>\n<p>\u201cNSA believes that currently published patches could provide a false sense of security for some infrastructures. Because BlackLotus integrates Shim and GRUB into its implantation routine, Linux administrators should also be vigilant for variants affecting popular Linux distributions.\u201d<\/p>\n<h2>Targeting a flaw in older boot loaders<\/h2>\n<p>BlackLotus targets Windows boot by exploiting a flaw in older boot loaders, or boot managers, to set off a chain of malicious actions that compromise endpoint security. This is achieved by exploiting the Baton Drop vulnerability to strip the Secure Boot policy and prevent its enforcement.<\/p>\n<p>BlackLotus shares some characteristics with <a href=\"https:\/\/www.scmagazine.com\/news\/content\/boothole-threatens-billions-of-linux-windows-devices\" target=\"_blank\" rel=\"noreferrer noopener\">Boot Hole<\/a>, a vulnerability discovered in 2020. Unlike Boot Hole, however, BlackLotus targets vulnerable boot loaders that have not been added to the Secure Boot Deny List Database (DBX) revocation list.<\/p>\n<p>\u201cBecause the vulnerable boot loaders are not listed within the DBX, attackers can substitute fully patched boot loaders with vulnerable versions to execute BlackLotus,\u201d the NSA wrote.<\/p>\n<p>\u201cAdministrators should not consider the threat fully remediated as boot loaders vulnerable to Baton Drop are still trusted by Secure Boot.\u201d<\/p>\n<p>As a result, a malicious actor exploiting Baton Drop could bypass Secure Boot and compromise the device.<\/p>\n<h2>Tips for defending against BlackLotus<\/h2>\n<p>Zachary Blum, the NSA\u2019s Platform Security Analyst, said protecting systems against BlackLotus was not a simple fix.<\/p>\n<p>\u201cPatching is a good first step, but we also recommend hardening actions, dependent on your system\u2019s configurations and security software used,\u201d he said.<\/p>\n<p>The NSA\u2019s information sheet recommends enabling the new optional protections provided in Microsoft\u2019s May patch, including mitigations to prevent rollback of the boot manager and kernel to versions vulnerable to Baton Drop and BlackLotus.<\/p>\n<p>\u201cThe optional mitigations \u2013 including a Code Integrity Boot Policy \u2013 should be enabled after the organization has updated its Windows installation, recovery, and diagnostic software to the latest available versions,\u201d the information sheet says.<\/p>\n<p>Because BlackLotus operates by placing an older Windows boot loader Extensible Firmware Interface (EFI) binary into the boot partition, and disabling Memory Integrity and BitLocker, the NSA recommends configuring endpoint security products to block these events outside of a legitimate, scheduled update.<\/p>\n<p>\u201cConfigure defensive software to scrutinize changes to the EFI boot partition in particular. Alternatively, leverage application allow lists to permit only known and trusted executables.\u201d<\/p>\n<p>It also recommends configuring endpoint security products and tools to monitor the composition of the EFI boot partition. \u201cLeverage these tools to look for unexpected changes in bootmgfw.efi, bootmgr.efi, or the introduction of additional unexpected EFI binaries (e.g., shimx64.efi or grubx64.efi). Changes to the boot partition are infrequent and warrant additional scrutiny.\u201d<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34747\/Microsofts-Bootkit-Patches-Offer-False-Sense-Of-Security-Against-BlackLotus-Threat-NSA-Says.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52476,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[10571],"class_list":["post-52475","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwaremicrosoftflawpatchnsa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft&#039;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft&#039;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-23T14:29:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/black-lotus.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Microsoft&#8217;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says\",\"datePublished\":\"2023-06-23T14:29:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/\"},\"wordCount\":646,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg\",\"keywords\":[\"headline,malware,microsoft,flaw,patch,nsa\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/\",\"name\":\"Microsoft's Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg\",\"datePublished\":\"2023-06-23T14:29:05+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg\",\"width\":854,\"height\":590},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,microsoft,flaw,patch,nsa\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwaremicrosoftflawpatchnsa\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Microsoft&#8217;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft's Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft's Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-23T14:29:05+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/black-lotus.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Microsoft&#8217;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says","datePublished":"2023-06-23T14:29:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/"},"wordCount":646,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg","keywords":["headline,malware,microsoft,flaw,patch,nsa"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/","url":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/","name":"Microsoft's Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg","datePublished":"2023-06-23T14:29:05+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says.jpg","width":854,"height":590},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/microsofts-bootkit-patches-offer-false-sense-of-security-against-blacklotus-threat-nsa-says\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,microsoft,flaw,patch,nsa","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwaremicrosoftflawpatchnsa\/"},{"@type":"ListItem","position":3,"name":"Microsoft&#8217;s Bootkit Patches Offer False Sense Of Security Against BlackLotus Threat, NSA Says"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52475"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52475\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52476"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}