Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion
15.1.2026 23:04:00 CET | Business Wire | Press Release
Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/
Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence
In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.
The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.
Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.
“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”
Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.
About Binarly
Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/
Contacts
Media Contact:
igor@binarly.io
(c) 2024 Business Wire, Inc., All rights reserved.
Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
SLB Announces Date for Second-Quarter 2026 Results Conference Call26.5.2026 19:00:00 CEST | Press Release
SLB (NYSE: SLB) will hold a conference call on July 24, 2026, to discuss the results for the second quarter ending June 30, 2026. The conference call is scheduled to begin at 9:30 a.m. U.S. Eastern time and a press release regarding the results will be issued at 7:00 a.m. U.S. Eastern time. To access the conference call, listeners should contact the Conference Call Operator at +1 (800) 715-9871 within North America or +1 (646) 307-1963 outside of North America approximately 10 minutes prior to the start of the call and the access code is 3440360. A webcast of the conference call will be broadcast simultaneously at https://events.q4inc.com/attendee/157027565 on a listen-only basis. Listeners should log in 15 minutes prior to the start of the call to test their browsers and register for the webcast. Following the end of the conference call, a replay will be available at www.slb.com/irwebcast until July 31, 2026, and can be accessed by dialing +1 (800) 770-2030 within North America or +1
Alipay Launches Next-Generation AI Payment Infrastructure, Debuts AI Wallet and Token Pay to Power Agentic Economy26.5.2026 17:20:00 CEST | Press Release
Alipay today introduced its full-stack AI payment solution to partners across industries, ranging from AI companies to traditional retailers, and debuted two new services — the world’s first AI Wallet and Token Pay — to support the agentic economy’s rapid growth. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260526337824/en/ Alipay Unveils Next-generation AI Payment Infrastructure This launch extends Alipay's next-generation AI payment infrastructure, building on its consumer-facing product Alipay AI Pay and its business-facing AI payment processing product. “While the essence of commerce remains unchanged in the age of AI, the emergence of AI agents is reshaping everything. Drawing on 22 years of technological expertise and commercial know-how, Alipay is building a new generation of AI payment services to accelerate the growth of the agentic commerce ecosystem,” said Cyril Han, CEO of Ant Group. AI Wallet: Giving Users Vis
Daiichi Sankyo Europe Reaffirms Commitment to Patient-Centred Care with Extensive Data Showcase at EAS Congress 202626.5.2026 17:00:00 CEST | Press Release
Daiichi Sankyo Europe (DSE) is pleased to announce its extensive scientific presence at the European Atherosclerosis Society (EAS) Congress 2026. The presentation of 15 abstracts, comprising both clinical trial analyses and real-world evidence, underscores the company's sustained investment in cardiovascular health and its mission to care for every heartbeat. The 15-abstract showcase provides a comprehensive look at the role of bempedoic acid in lipid management. This includes post-hoc analyses in collaboration with Esperion Therapeutics from the Phase 3 CLEAR Outcomes trial exploring its impact on stroke and venous thromboembolism (VTE) incidence.5,6 There are also real-world findings from the MILOS registry, including a dedicated sub-analysis investigating the effectiveness of bempedoic acid across various background therapies.1,2,3,4 Results reinforce consistent effectiveness and safety profile of bempedoic acid across various EU countries and regardless of patients’ existing treatm
OpenRouter Raises $113 Million CapitalG-led Series B as Weekly Volume Explodes to 25T Tokens26.5.2026 15:15:00 CEST | Press Release
OpenRouter, the AI model exchange, today announced a $113 million Series B led by Alphabet’s independent growth fund, CapitalG, with participation from investors including NVentures (NVIDIA’s venture capital arm), ServiceNow Ventures, MongoDB Ventures, Snowflake Ventures, Databricks Ventures, alongside existing investors including Andreessen Horowitz and Menlo Ventures. OpenRouter’s volume has surged to 25 trillion tokens per week (100 trillion tokens per month), representing a 5X increase from the 5 trillion tokens processed per week just six months ago. The explosion in token demand illustrates how quickly enterprises are deploying agents and scaling AI across multiple models and providers. OpenRouter’s infrastructure manages and optimizes inference and provides access to 400+ models across leading AI providers, including Anthropic, Google, OpenAI, xAI, and DeepSeek, among others. The platform is used by over 8 million global users, including AI-native startups and large enterprises,
Xsolla Expands Its Community Management Tools for Creators, Community Leaders, and Resellers26.5.2026 15:00:00 CEST | Press Release
Xsolla, a leading global video game commerce company, today announced three simultaneous expansions of its community management tools and products. As the creator economy continues to reshape how games are discovered and the industry accelerates its shift toward direct-to-consumer commerce, Xsolla is building on its community management tools for creators, community leaders, and emerging markets, and will showcase them at TwitchCon Rotterdam later this month. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260526596720/en/ Graphic: Xsolla The games industry has never had a shortage of people who drive player acquisition, loyalty, and commerce; it's had a shortage of infrastructure that recognizes them. Creators stream it. Community leaders build a culture around it. Local resellers get it into the hands of players in markets traditional channels can't reach. Each operates at the center of how games are discovered, adopted, an
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom