Business Wire

Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion

15.1.2026 23:04:00 CET | Business Wire | Press Release

Share

Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/

Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence

In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.

The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.

Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.

“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”

Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.

About Binarly

Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/

Contacts

Media Contact:
igor@binarly.io

(c) 2024 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Westlake Epoxy Expands Distribution Relationship with Brenntag to India18.2.2026 02:30:00 CET | Press Release

Westlake Corporation (NYSE: WLK) today announced that Westlake Epoxy will expand its long‑standing distribution relationship with Brenntag to South and West India. The agreement builds on a successful collaboration across Europe, North and South America, and Southeast Asia, extending Westlake Epoxy’s reach into one of the world’s fastest‑growing coatings, adhesives and construction markets. Under the expanded collaboration, Brenntag will distribute Westlake Epoxy’s established portfolio of epoxy solutions for coatings, adhesives and construction applications, including the EPON™, EPIKOTE™, EPIKURE™ and EPI‑REZ™ product lines. Customers are expected to benefit from reliable local supply, technical service and application‑focused formulation support tailored to regional requirements. India’s coatings, adhesives and construction sectors continue to grow, driven by infrastructure investment, urbanization and increasing performance expectations. By combining Westlake Epoxy’s proven epoxy te

Compass Pathways Launches Proposed $150.0 Million Public Offering17.2.2026 22:06:00 CET | Press Release

Compass Pathways plc (Nasdaq: CMPS), a biotechnology company dedicated to accelerating patient access to evidence-based innovation, announced today the launch of a proposed public offering of $150.0 million of American Depositary Shares (“ADSs”), each representing one ordinary share, and in lieu of ADSs, to certain institutional investors, pre-funded warrants to purchase ADSs. All securities are being offered by Compass Pathways. Compass Pathways expects to grant the underwriters a 30-day option to purchase up to an additional $22.5 million of ADSs at the public offering price, less the underwriting discounts and commissions . The proposed offering is subject to market and other conditions, and there can be no assurance as to whether or when the proposed offering may be completed, or as to the actual size or terms of the proposed offering. Jefferies, TD Cowen, Cantor and Stifel are acting as joint book-runners for the proposed offering. H.C. Wainwright & Co. is also acting as lead mana

Lattice Launches Joint Cyber Resilience Reference Kit with EXOR International and TrustiPhi to Simplify Secure Device Development17.2.2026 22:00:00 CET | Press Release

Lattice Semiconductor (NASDAQ: LSCC), the low power programmable leader, today announced a Cyber Resilience Reference Kit designed to help industrial and edge device manufacturers accelerate secure system design, developed in collaboration with EXOR International and TrustiPhi. Built on the Lattice MachXO3D™ secure control FPGA, EXOR International’s industrial edge platform, and TrustiPhi’s integrated security orchestration platform, the kit enables hardware‑rooted trust, secure lifecycle management, and industrial‑grade connectivity to accelerate cyber resilient system design. “Security can no longer be an afterthought, especially at the industrial edge. With this collaboration, we’re giving customers a practical, integrated way to accelerate secure system development and support emerging requirements such as the EU Cyber Resilience Act,” said Karl Wachswender, Senior Principal System Architect Industrial, Lattice Semiconductor. “Through our early access program, major industrial comp

Capvidia and Hexagon to Host Live Webinar on Building a “Real” Digital Thread from Design to Inspection Using MBD, QIF, and PC-DMIS17.2.2026 19:50:00 CET | Press Release

Capvidia, a global leader in Model-Based Definition (MBD) and model-based interoperability, announced it will co-host a live webinar with Hexagon focused on creating a seamless digital thread that connects design, production, and inspection using MBD, the Quality Information Framework (QIF), and Hexagon’s PC-DMIS metrology software. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260217927277/en/ Connecting design to inspection—without the rework. Capvidia + Hexagon show how MBD + QIF power a real digital thread into PC-DMIS for faster, traceable, more accurate inspection. Titled “Connected for Success: Unlock seamless data flow and precision from design to inspection”, the webinar will take place on Wednesday, February 25, 2026, at 9:00 AM EST / 2:00 PM GMT. Attendees will see a practical demonstration of how an integrated approach can reduce manual data entry, minimize translation errors, preserve design intent, and improve

ProAmpac Pushes the Limits of Fiber Packaging with New High Barrier Packaging Innovation Platform17.2.2026 18:08:00 CET | Press Release

ProAmpac, a global leader in flexible packaging and material science, announces the expansion of its ProActive Recyclable® RP-2000 High Barrier Series. This curbside recyclable, fiber-based packaging platform is designed to help brands transition away from traditional non-recyclable high-barrier multilayer structures, such as paper/foil, paper/metalized polyethylene terephthalate (METPET), and certain film laminations. The RP-2000 platform provides strong barriers to oxygen and moisture, making it well-suited for sensitive dry food products such as oatmeal, granola, cereal, spices, snacks, dried fruits, and nuts. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260217779741/en/ ProAmpac's RP-2000MHB Series “Supporting the growing Fiberization of Packaging® movement, and as adoption of fiber-based structures accelerates, it is critical that ProAmpac continues to expand the functional performance envelope of paper-based material

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye