Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Security leaders discuss NSA guide to mitigate BlackLotus threat

By Rachelle Blair-Frasier, Editor in Chief
computer code on computer screens

Image via Unsplash

June 28, 2023

The National Security Agency (NSA) is warning of a known vulnerability in the Microsoft Windows secure startup process that malicious actors could use to bypass Secure Boot protection and execute BlackLotus malware.
 
In an effort to help enterprise security professionals mitigate this threat, the NSA recently released the “BlackLotus Mitigation Guide” Cybersecurity Information Sheet (CSI) guide which provides an overview of recommended actions to detect and prevent malicious activities associated with BlackLotus.
 
“Protecting systems against BlackLotus is not a simple fix,” NSA’s Platform Security Analyst Zachary Blum said in a relase. “Patching is a good first step, but we also recommend hardening actions, dependent on your system’s configurations and security software used.”

Given the scale that this vulnerability exists, John Gallagher, Vice President of Viakoo Labs at Viakoo, said it makes sense that NSA would ask organizations to pay attention and make plans to address it. 

“Unified Extensible Firmware Interface (UEFI) vulnerabilities, as the guidance from NSA shows, are particularly difficult to mitigate and remediate because they are in the earliest stage of software and hardware interactions,” Gallagher said. “The guidance NSA is providing is critically important as a reminder to pay attention to boot-level vulnerabilities and have a method to address them.”  

Gallagher added that until Microsoft has a more comprehensive fix — planned for early 2024 — the NSA guide gives organizations that may be impacted a plan of attack so they can estimate what resources they will need.  

“Given the manual nature of NSA’s guidance, many organizations will find that they don’t have the resources needed to fully remediate this vulnerability,” Gallagher said. “Additional measures like use of network access control and traffic analysis should also be used until Microsoft can provide a more complete fix.”  

According to the NSA release, “BlackLotus exploits a known vulnerability called ‘Baton Drop,’ CVE-2022-21894, which bypasses security features during the device’s startup process, also known as Secure Boot. The malware targets Secure Boot by exploiting vulnerable boot loaders not added into the Secure Boot Deny List Database (DBX).”

Callie Guenther, Cyber Threat Research Senior Manager at Critical Start, said the BlackLotus bootkit, which bypasses the UEFI Secure Boot, poses a significant threat to organizations. 

“The bootkit allows threat actors to execute malware before the operating system and security measures become active, providing them with persistent control and the ability to subvert security defenses,” Guenther said. “BlackLotus's ability to evade traditional security defenses and subvert logging and countermeasures makes it challenging for organizations to detect and respond to attacks. This highlights the need for robust defensive measures and security solutions that can identify and mitigate such advanced threats.”

Guenther added that BlackLotus's ability to evade traditional security defenses and subvert logging and countermeasures makes it challenging for organizations to detect and respond to attacks which highlights the need for robust defensive measures and security solutions that can identify and mitigate such advanced threats.
 
“The incident highlights the potential vulnerabilities associated with firmware, particularly UEFI Secure Boot implementations,” Guenther said. “Organizations need to recognize the importance of validating the integrity of their servers, laptops and workstations, including regularly updating firmware and monitoring for any indications of compromise,” 

Guenther stressed the importance of collaboration and threat intelligence sharing.

“Given the evolving threat landscape, organizations can benefit from collaborating and sharing threat intelligence to stay updated on emerging threats, tactics and techniques used by threat actors,” Guenther said. “Sharing information and insights within the cybersecurity community can help organizations collectively strengthen their defenses against such threats.”


KEYWORDS: cyber attack cyber threat firmware updates malware Microsoft Security mitigation national security agency NSA vulnerability

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Rachelle blairfrasier headshot white

Rachelle Blair-Frasier is Security magazine’s Editor in Chief. Blair-Frasier handles eMagazine features, as well as writes and publishes online news and web exclusives on topics including physical security, risk management, cybersecurity and emerging industry trends. She helps coordinate multimedia content and manages Security magazine's social media presence, in addition to working with security leaders to publish industry insights. Blair-Frasier brings more than 15 years of journalism and B2B writing and editorial experience to the role.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Cybersecurity hand graphic

    Security leaders discuss new SEC disclosure rule as deadline nears

    See More
  • Broken glass

    Security leaders discuss the new vulnerability added to CISA’s catalog

    See More
  • group of women sitting around an office table

    Security leaders discuss how to make space for women in the workplace

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • The Complete Guide to Physical Security

  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

See More Products

Events

View AllSubmit An Event
  • September 9, 2025

    Actionable Strategies to Mitigate Active Assailant Risk

    ON DEMAND: Active assailant incidents are surging — Are you ready? This dynamic session will equip attendees with actionable, real-world tactics to protect their people and maintain business continuity when it matters most.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing