Business Wire

Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion

15.1.2026 23:04:00 CET | Business Wire | Press Release

Share

Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/

Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence

In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.

The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.

Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.

“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”

Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.

About Binarly

Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/

Contacts

Media Contact:
igor@binarly.io

(c) 2024 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Kao’s Laurier Launches New Brand Communication Initiative across Asia: Strengthening Global Integration as a Core Brand in Kao’s Asian Business4.3.2026 03:10:00 CET | Press Release

Starting on International Women’s Day, March 8, Kao Corporation (TOKYO:4452) will launch new brand communication campaign in nine Asian countries and regions for its feminine sanitary product brand, Laurier, which is the core of its Asian business. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260303996141/en/ Laurier Campaign Key Visual Laurier aims to help create more supportive and understanding environments around menstruation, so that women can feel more at ease, both physically and emotionally, under the key message “Comfort, Made Together,” which will be implemented simultaneously across Asia. Kao aims to further develop Laurier as a global brand. Laurier, one of the core brands supporting Kao’s consumer care business in Asia, has been promoting globally integrated operations since 2023. Across all nine Asian countries and regions including Japan, Laurier has been working to unify product specifications and consolida

FIFA World Cup 2026™ Mascots and Representatives from the New York New Jersey Host Committee, U.S. Soccer Federation, Mexico Football Federation and Canada Soccer Light the Empire State Building to Celebrate 100 Days to Go Until the FIFA World ...3.3.2026 23:06:00 CET | Press Release

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260303105064/en/ FIFA World Cup 2026™ Mascots and Representatives from the New York New Jersey Host Committee, U.S. Soccer Federation, Mexico Football Federation and Canada Soccer Light the Empire State Building to Celebrate 100 Days to Go Until the FIFA World Cup 2026™ FIFA World Cup 2026™ Mascots and Representatives from the New York New Jersey Host Committee, U.S. Soccer Federation, Mexico Football Federation and Canada Soccer Light the Empire State Building to Celebrate 100 Days to Go Until the FIFA World Cup 2026™ On Tuesday, March 3, the Empire State Building will rotate in the colors of the flags of the three host countries – the United States, Canada, and Mexico – to mark 100 days to go until the FIFA World Cup 2026™. Earlier today, the Empire State Building hosted a special tower lighting ceremony with Alex Lasry, CEO of the FIFA World Cup 26™ New York New Jersey Host C

SES Publishes 2025 Annual Report3.3.2026 21:41:00 CET | Press Release

SES S.A. has today published its 2025 Annual Report, following the announcement of the company’s full year financial results for the 12 months ended 31 December 2025. Follow us on: Twitter | Facebook | YouTube | LinkedIn | Instagram Read our Blogs > Visit the Media Gallery > About SES At SES, we believe that space has the power to make a difference. That’s why we design space solutions that help governments protect, businesses grow, and people stay connected—no matter where they are. With integrated multi-orbit satellites and our global terrestrial network, we deliver resilient, seamless connectivity and the highest quality video content to those shaping what’s next. Following our Intelsat acquisition, we now offer more than 100 years of combined global industry leadership—backed by a track record of bringing innovation “firsts” to market. As a trusted partner to customers and the global space ecosystem, SES is driving impact that goes far beyond coverage. The company is headquartered

Xsolla Expands Global Payment Coverage Across 18 Markets With 6 Trusted Local Payment Methods to Help Developers Reach New Players Worldwide3.3.2026 18:00:00 CET | Press Release

Xsolla, a global video game commerce company that helps developers launch, grow, and monetize their games, today announced a major expansion of its global payments portfolio across 18 markets in Europe, the Middle East, Africa, and Asia. As developers continue to expand into high-growth and emerging markets, this expansion enables developers to reach new paying users, improve conversion rates, and deliver payment experiences tailored to local player preferences. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260303816373/en/ Graphic: Xsolla The newly supported payment methods include: Local Amazon Pay in Japan, with over 100 million registered Amazon Japan accounts, provides fully localized checkout experiences in Japanese Yen Zain Cash in Iraq is expanding access to mobile-first payment options in a rapidly growing economy, where mobile numbers serve as primary digital identities and mobile adoption is broad across a popula

SES Announces Annual General Meeting of Shareholders3.3.2026 17:42:00 CET | Press Release

SES: Société Anonyme RCS Luxembourg B 81267 Notice is hereby given of the Annual General Meeting of SES, Société Anonyme, to be held at the Company’s registered office at Château de Betzdorf, L-6815 Betzdorf (the “Company”), Luxembourg, on Thursday 2 April 2026 at 10:30 a.m. CET AGENDA Attendance list, quorum and adoption of the agenda Nomination of a secretary and of two scrutineers Presentation by the Chairman of the Board of Directors of the 2025 activities report of the Board of Directors Presentation of the main developments during 2025 and of the outlook Presentation of the audit report Approval of annual financial statements, balance sheet and profit and loss account as of 31 December 2025 Approval of consolidated financial statements as of 31 December 2025 Allocation of 2025 profits and transfers between reserve accounts Discharge of the members of the Board of Directors Determination of the number of Directors Confirmation of the co-optation of Joseph Cohen and determination o

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye