Visualização de leitura
Sideloading on Android: What it is, why it’s risky, and how to do it more safely
A Google spokesperson announced on Reddit that it has started rolling out the first version of its Advanced Flow, designed to make installing apps from unverified developers safer.
Let us explain what sideloading is, why Google Play is not 100% safe, what to look for when you’re sideloading so you can do it more safely, and how Google’s Advanced Flow helps with that.
What is sideloading?
Sideloading lets Android users install apps from outside Google Play. It can be useful, but it also creates opportunities for scams and malware.
Android’s openness is one of its enduring strengths. You are not limited to a single app store: You can install apps from a developer’s website, an alternative marketplace, an enterprise portal, or a file shared directly with you.
That is called sideloading. It is not automatically dangerous, but it removes some of the guardrails that come with conventional app-store distribution. Getting apps from the Google Play Store itself is no guarantee of safety, but there is at least some vetting. Google says it blocked more than 1.75 million policy-violating apps from being published in 2025 and banned more than 80,000 developer accounts associated with harmful apps.
There are several reasons for sideloading:
- The developer distributes an app directly from its own website
- An app is unavailable in your country or on Google Play
- An alternative app repository offers what you’re after, for example open-source software
- You need an enterprise, beta, or specialized app
- You want to install a version that is not currently offered through Google Play
But malware authors and online scammers use the same flexibility. They may impersonate banks, delivery services, government agencies, crypto platforms, news readers, or job recruiters, then urge victims to install an app to “secure” an account, receive a payment, or resolve an invented problem.
Google Play is not a free pass
Google Play has review processes, policy enforcement, developer controls, and Google Play Protect. It also runs ongoing checks after an app is published. Those measures meaningfully reduce risk, but they do not make every listing harmless or every developer trustworthy.
Threats that can still surface through official channels include:
- Trojans disguised as useful utilities, games, or financial apps
- Adware and apps that misrepresent their behavior
- Subscription traps and deceptive billing practices
- Data-harvesting apps that request more access than they need
- Sleeper apps that change behavior after passing an initial review
Google Play Protect checks Play Store apps before download and also scans apps from other sources. It can warn about, disable, or remove potentially harmful apps, but it should be viewed as one layer of security, not a substitute for scrutinizing an app before installing it.
In short, “available on Google Play” is a positive signal, not a security verdict.
Why sideloading requires attention
The main difference between installing from a recognized store and downloading an APK from elsewhere is not simply the file format. It is the trust chain.
When you sideload, you may have fewer assurances about:
- Who created the app
- Whether the file has been altered or repackaged
- Whether the download site is impersonating a legitimate developer
- Whether you will receive genuine updates
- Whether a scammer is manipulating you into disabling security protections
Social engineering is often the decisive factor. A convincing caller, pop-up, text, or chat message may insist that installing an app is urgent. The attacker’s goal is often to make the victim bypass warnings before they have time to question the request.
Treat any unexpected request to install an app as suspicious, especially when it comes with urgency, secrecy, a promise of money, or a claim that your bank, government, employer, or device provider requires it.
A legitimate bank, government agency, law-enforcement organization, or technical-support provider should not call or message you and instruct you to install an APK or weaken Android security settings.
How to sideload more safely
Sideload only when you have a specific reason for it, and make sure the decision came from you rather than an unexpected message or phone call.
- Start at the developer’s official site. Don’t use sponsored search results, random download portals, links sent by strangers, or lookalike domains.
- Verify the developer independently. Check the publisher’s official website, documentation, public code repository, and trusted community channels. The information supplied on the download page alone is not enough.
- Prefer established repositories. If an app is distributed outside Google Play, use a source with a strong reputation for provenance and signature verification where possible. For advanced users, it can be useful to compare an APK’s signing certificate or cryptographic hash against a value published by the developer. That is not practical for everyone, but it can help detect fakes.
- Do not install apps under pressure. End the call, close the chat, and independently research the claimed organization using contact details you find yourself.
- Keep Google Play Protect enabled. It scans apps during installation and periodically afterward, including apps installed from outside Google Play.
- Review permissions before and after installation. Be especially cautious if a simple app wants access to accessibility services, SMS messages, notifications, device administration, contacts, or screen recording.
- Keep Android and apps updated. Security fixes can protect against both operating-system flaws and known malicious app behavior.
- Use reputable mobile security software. A separate security layer can help identify risky behavior and provide additional visibility into potentially unwanted or malicious apps.
- Remove permissions and uninstall apps you no longer trust or use. An app that seemed harmless at installation can become a liability if its developer abandons it or changes direction.
How Google’s new Advanced Flow helps
Google is rolling out Advanced Flow for installing apps from developers that have not completed Android’s new identity-verification process. The feature is intended for users who understand the risks of installing unverified software but still need that flexibility.
The design is notable because it targets social-engineering attacks as well as malware. Instead of allowing an immediate, one-tap override, the flow requires users to:
- Enable developer mode in system settings. This is easy enough and helps prevent accidental or one-tap bypasses often used in high-pressure scams.
- Complete a quick safety check to make sure that no one is talking you into turning off your security. Scammers often pressure victims into disabling protections.
- Restart your device, which cuts off any remote access or active phone calls a scammer might be using to guide you.
- Wait one day, then confirm the change using biometrics, such as fingerprint or face unlock, or your device PIN. This one-time, one-day delay breaks the urgency scammers rely on, giving you time to think.
Once you have completed the process, you can choose to allow installs from unverified developers for seven days or indefinitely.
Advanced Flow does not mean Google Play is risk-free, nor does it make unverified apps inherently malicious. Developer verification establishes accountability: It connects an app to a verified developer identity, but it does not establish that every app is benign or suitable for every user.
At the end of the day, it’s up to you. Install apps because you chose them after checking the source, not because someone else manufactured an emergency.
Whether an app comes from Google Play or an external source, pause before installing. Check who made it, why it needs the permissions it asks for, whether the download route is trustworthy, and refuse when a stranger is trying to rush you. That little friction is a feature, not just a nuisance.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
How to use GitHub safely
GitHub is rapidly becoming the go-to platform for sharing software. Originally built for developers to collaborate on code, it now hosts millions of projects ranging from hobby scripts to widely used applications. That popularity, however, has also made it an attractive delivery platform for cybercriminals.
For most home users, GitHub is not something you need to use in your daily life. You might encounter it when searching for a tool, following installation instructions, or trying out something recommended on a forum or social media. And that’s where the risk begins. GitHub is not an app store. It does not check every repository for safety, and anyone can upload code, including cybercriminals.
Recent campaigns highlight how this can be abused. We’ve seen cybercriminals create convincing repositories that impersonate well-known brands like Malwarebytes and LastPass, offering downloads that are anything but legitimate. In other cases, hundreds of repositories have been spun up to distribute Trojanized versions of popular software. These pages often look polished, include documentation, and even fake user engagement to appear trustworthy.
We’ve also seen campaigns targeting specific groups, including retro-gamers, people looking for free AI agents, OpenClaw users, and people searching for AppleCare+ service.
What exactly is GitHub, and when should you use it?
At its core, GitHub is a code hosting platform. Developers use it to share source code, track changes, and collaborate. For home users, its legitimate uses include:
- Accessing open-source tools that are not available elsewhere
- Downloading updates or beta versions directly from developers
- Viewing the source code to understand how software works
For developers, GitHub is indispensable. For home users, it’s optional and should be approached with the same caution you’d apply to downloading files from anywhere else on the internet.
Unless you have a specific reason, you don’t need to download software from GitHub. Most mainstream applications have official websites or trusted distribution channels. If you find yourself on GitHub because a search result or online guide led you there, that’s a good moment to slow down and verify what you’re looking at.
How to stay safe
Malicious repositories often rely on a mix of social engineering and technical shortcuts. Some red flags include:
- Brand impersonation: The repository claims to be from a well-known company, but the account name doesn’t match the official organization. Attackers often use subtle variations or newly created accounts.
- Recently created accounts: A repository tied to an account that was created days or weeks ago is a warning sign, especially if it claims to host established software.
- Unusual download methods: Legitimate projects typically provide source code and, where appropriate, clearly documented releases. Be cautious if you’re encouraged to download executables directly from obscure links or archives.
- Inflated or fake activity: Star counts, forks, and issues can be manipulated. A repository with lots of stars but little meaningful discussion or contribution history may not be what it seems.
- Poor or generic documentation: Many malicious repositories copy text from legitimate projects but fail to maintain consistency. Look for vague instructions, broken links, or mismatched branding.
- Security warnings ignored: If your browser, antivirus, or operating system flags a download, take it seriously. These warnings are often your first line of defense.
Cybercriminals are increasingly exploiting trusted platforms to blend in and bypass traditional defenses. Recognizing that shift is key. The next time you land on a GitHub page offering a convenient download, take a closer look. A few extra seconds of scrutiny can save you from installing something you never intended.
- Use an up-to-date, real-time anti-malware solution and don’t ignore its warnings—even if, or especially if, the “developer” tells you to expect them.
- Remember that GitHub repositories do not undergo a vetting process. The responsibility for deciding what you can safely download ultimately lies with you.
- It’s usually safer to start from the vendor’s official website and follow its link to GitHub, rather than the other way around.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
How to tell if an image is AI-generated
A photo of an injured dog by the roadside. A dating profile with pictures that look almost too perfect. A donation appeal showing a family stranded on a rooftop after a flood.
Scammers are already using AI-generated images to support fake stories, build trust, and persuade people to send money or share personal information.
Instead of asking whether an image looks real, it’s better to ask whether there’s any evidence that it’s genuine.
What you actually need to know
You can’t reliably spot AI images by eye anymore. Advice like “count the fingers” or “look for garbled text” is becoming outdated because today’s AI image generators usually get those details right.
Instead of looking harder, verify the image and be skeptical of the story around it.
- Distrust the situation, not just the picture. These scams rely on urgency and emotion to push you into acting before you’ve had time to think.
- Check whether the image has appeared before. A reverse image search takes seconds and can often reveal where it really came from.
- Use an official verification tool when it matters. Google’s Gemini app can check for AI watermarks and provenance data. It’s not foolproof, but it provides useful evidence.
If an image is being used to ask for money or personal information, don’t treat it as proof until you’ve verified it.
Common AI image scams
In each case, the image is there to make the request for money more believable.
Fake lost pets
Scammers post AI-generated photos of distressed animals in local groups before asking for “rehoming fees” or other payments. Because the image was generated rather than stolen, a reverse image search may not reveal an original source.
“I found your pet”
Scammers target people searching for a missing pet, send them an AI-generated photo, then ask for a reward or deposit before disappearing.
Dating profiles
Photos that are flawless and consistent across every angle because they were never a real person. A video call helps, but it isn’t proof. Modern real-time deepfakes can pass simple tests like holding up fingers in front of the camera. Ask for something unscripted instead, such as turning their head or picking up a random object, and be wary of anyone who refuses to get on a call at all.
Fake artists
An AI-generated portfolio presented as original work on X, Instagram, or Fiverr to win paid commissions. Sometimes the scammer disappears after taking a deposit. Other times they deliver a “finished” piece that turns out to be AI-generated rather than the original artwork the buyer paid for. A genuine artist can usually show sketches, layered files, or work-in-progress images. Someone using an AI-generated portfolio can’t.
Fake fundraising appeals
Alongside real disasters, fabricated images of sick children, injured animals, or families in crisis are widely shared to encourage donations or simply attract attention. Some depict people who don’t exist at all. The more emotional the image, the less likely people are to stop and verify it.
Why visual clues aren’t enough anymore
Spotting a fake used to mean spotting edits, such as a repeating background, a shadow in the wrong place, or artefacts around a pasted-in object. That worked because manipulated images usually started with a real photo, leaving clues behind.
AI-generated images are different. They’re created from scratch, with no original image underneath, so those kinds of editing mistakes often don’t exist.
Visual clues are still worth a glance. Look for inconsistent jewellery, unusual lighting, distorted reflections, or odd movement in video. But don’t assume an image is genuine just because you can’t spot anything wrong.
How to check if an image is AI-generated
Reverse image search
Google Lens, TinEye, and Bing Visual Search can often reveal where an image first appeared online.
No matches don’t necessarily mean an image is fake. Personal photos and newly published images often won’t appear anywhere else. But if someone claims an image has been circulating for days or comes from a widely reported event, a complete lack of history is worth questioning.
Provenance tools
Some images contain information about where they came from or whether AI was used to create them.
The two most common types of provenance information are:
- Content Credentials (C2PA): Records information about how an image was created or edited. It is supported by companies including Adobe, Google, Microsoft, and Sony.
- SynthID: Google’s invisible watermark embedded into supported AI-generated images. It now also covers images created with ChatGPT and DALL·E through a partnership announced in 2026.
Verification tools such as the Gemini app or OpenAI Verify look for this information to help determine whether an image was created with AI.
We created an AI-generated image and checked it using OpenAI Verify.

OpenAI Verify correctly identified it as AI-generated.

Keep in mind that if no watermark is found, it doesn’t mean the image is genuine. It simply means no watermark was detected.
Where these checks fall short
- Messaging apps strip the evidence. WhatsApp, iMessage, and Facebook re-encode images when they’re uploaded, often removing embedded credentials. That’s one reason the pixel-based SynthID watermark is useful: it can survive changes that strip metadata.
- “Not found” is the most misread result. Most real photos don’t contain any provenance information. A result that says no watermark or credentials were found doesn’t mean the image is genuine. It simply means no signal was detected.
- A valid credential proves the pipeline, not the truth. It confirms which device or app produced the file and when, but not that what it shows actually happened. For example, someone could photograph a screen playing a deepfake video. The credential would be completely valid because the camera really did take that picture. It just can’t tell you the content on the screen was fake.
- Some “SynthID detector” sites are misleading. Reading the actual SynthID watermark requires technology only Google and its approved partners have access to. That means only official tools, such as Google’s own apps and OpenAI Verify, can directly verify it. Third-party websites using the “SynthID” name are usually estimating whether an image is AI-generated, not reading the actual watermark.
If you think you’ve been caught by an AI image scam
- Save screenshots of the profile, images, and messages before they disappear.
- Run the image through a reverse image search and, where possible, an official AI verification tool.
- If you shared financial information, contact your bank immediately and change any passwords you’ve reused elsewhere.
- Stop sending money. Don’t make “one more” payment in the hope of recovering what you’ve already lost.
- Report the account to the platform and to your national fraud reporting service, such as the FTC in the US or Report Fraud in the UK.
- Warn others in the same community if appropriate. Many of these scams spread through trusted groups and personal recommendations.
The bottom line
An image used to be reasonable proof that something happened. That’s no longer the case. A convincing, original image can now be created in seconds, with no previous history to trace.
The good news is that verification tools are becoming easier to use. They’re not perfect, but a habit of scepticism, reverse image searches, and official verification tools is far more reliable than trying to spot visual mistakes.
Check the source, resist the urgency, and don’t let a picture do your thinking for you.
Which tool should I use? A quick reference
| Tool | Checks |
|---|---|
| Gemini (upload the image in the Gemini app, Google Search, or Chrome and ask if it was created with AI) | SynthID watermark and Content Credentials |
| Google SynthID Detector | SynthID watermark in images, video, and audio |
| OpenAI Verify | SynthID and Content Credentials in ChatGPT, DALL·E, and API-generated content |
| Reverse image search with Google Lens / TinEye / Bing Visual Search | Matches the image against copies on the web to find where else it appears |
How to interpret the results
- Watermark found: The file was generated using a supported AI system.
- No watermark found: No signal was detected. This is the normal result for most genuine photos, but it doesn’t rule AI in or out.
- Content Credentials found: The file contains provenance information about how it was created or edited. This helps establish its origin, but it doesn’t prove the scene itself is genuine.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Travel scams are everywhere. Here’s how to avoid them
Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms. Combined with frequent travel scams and recurring data breaches in the travel and hospitality sector, it creates plenty of opportunities for criminals.
This guide covers the most common risks when making travel reservations and explains how to avoid them. Save the adventure for your destination.
Travel bookings combine high-value payments with urgency and emotional decision-making. Attackers love that for several reasons:
- Large upfront payments make scams profitable.
- Booking confirmations often contain valuable personal data, such as names, travel dates, contact details, and sometimes passport information.
- Travelers are more likely to act quickly and overlook red flags.
- Travel and hospitality companies are frequent breach targets due to complex IT environments and third-party integrations.
Recent years have seen repeated breaches involving hotel chains, booking platforms, cruise operators, and airlines, exposing everything from email addresses to passport numbers.
Common travel-related scams
Fake booking websites
Attackers create convincing clones of airline, hotel, and travel booking websites, often promoted through online ads or SEO poisoning (manipulating search engine results). Victims enter payment details, receive fake confirmations, and only discover the fraud later.
Last year we uncovered a campaign using fake Booking.com websites that tricked visitors into infecting their own devices with a Remote Access Trojan (RAT).
Phishing messages about reservation problems
Emails, texts, or messaging app notifications may claim there’s a problem with your booking and urge you to click a link, open an attachment, or call a number. The scammers often impersonate legitimate travel brands and may include real stolen data from previous breaches.
Earlier this year, we wrote about a Booking.com breach that provided scammers with a lot of useful information that could make their messages appear more convincing.
Vacation rental fraud
Scammers post fake listings or hijack legitimate ones on rental platforms. They typically encourage off-platform communication or payments to avoid built-in protections.
In 2024, one of our researchers encountered exactly this type of scam. A supposedly legitimate Airbnb listing in Amsterdam turned out to be fake, and the scammer sent an email claiming to be from TripAdvisor in an attempt to collect payment details.
“Too good to be true” deals
Deep discounts on flights or accommodation are used to lure victims into paying for offers that don’t exist.
If a deal seems unusually generous, look for the catch. Be especially cautious when advertisers claim the offer will end very soon. Creating urgency is one of the oldest tricks in the scammer playbook.
Booking.com impersonation scams
Booking.com has become an increasingly popular brand for scammers to impersonate. According to our—anonymized—Scam Guard data, we’ve recently seen:
- Fake cashback emails promising a €435 refund that lead to phishing websites
- In-app messages requesting an additional reservation fee
- Emails containing PDF attachments that require a “secure viewer,” which turns out to be malware
- WhatsApp messages claiming credit card details are missing and directing users to phishing sites
- Text messages linking to fake Booking.com pages and demanding card verification before a deadline
The number of scams impersonating Booking.com has been growing. Since the breach disclosed in April, Scam Guard data shows a 56% increase in Booking.com-related scams compared to the previous period, with weekly volume up consistently across five straight weeks.
How to book travel safely
There are a few simple things that can dramatically reduce your risk:
- Use secure payment methods. Credit cards offer better fraud protection than debit cards or bank transfers. Never pay anyone asking for payment in cryptocurrencies or gift cards.
- Stick to trusted platforms. Even though these are not guaranteed to be safe, using them is better than gambling on an unknown platform.
- Don’t click on sponsored search results. I cannot say this often enough.
- Verify the existence of the booked accommodation through other channels.
- Treat requests to move communication or payment to another platform as suspicious.
- Consider urgent language, unexpected attachments, and mismatched sender domains as red flags.
- Downloads needed to open an attachment are not to be trusted. These downloads often turn out to be malware. To block and remove malware, use an up-to-date, real-time anti-malware solution.
Pro tip: Malwarebytes Browser Guard will block known phishing websites and can even recognize suspicious websites that are not in our database yet.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
How to Recover Data from iCloud Backup Without Resetting Your iPhone
Your Windows PC has a security deadline in June 2026
A Secure Boot certificate refresh is rolling out across supported Windows devices through Windows Update. In June 2026, the Secure Boot certificates that have shipped inside Windows since 2011 begin to expire, and Microsoft is replacing them with new 2023-dated certificates.
The good news: If you keep your PC updated, you probably won’t need to do anything. The bad news: Some older devices may not transition cleanly. Your PC won’t suddenly stop working, but over time it could miss important boot-level security protections without you realizing it.
Here’s what’s going on, why it matters, and how to check that your machine is on the right side of the deadline.
What is Secure Boot, and what’s expiring?
Secure Boot is a UEFI firmware feature built into virtually every PC sold since around 2012. It runs before Windows even starts loading, and its job is to verify that the boot loader and early boot components have been signed by a trusted party. If something tries to insert itself into the boot chain that isn’t on the trust list—a bootkit, for example—Secure Boot refuses to let it run.

The “trusted party” part is the crucial bit. Trust is established through cryptographic certificates baked into your motherboard firmware. The current certificates were issued in 2011 and are now reaching expiration. Three specific certificates are involved:
- Microsoft Corporation KEK CA 2011: expires June 24, 2026
- Microsoft UEFI CA 2011: expires June 27, 2026
- Microsoft Windows Production PCA 2011: expires October 19, 2026
Microsoft is replacing them with a 2023-dated set, including Windows UEFI CA 2023 and Microsoft Corporation KEK 2K CA 2023. According to Microsoft engineers speaking during a March 2026 AMA session, the new certificates are valid until 2038, and a separate post-quantum cryptography transition is planned for around 2030 for future hardware.
“Will my computer stop working?”
No. This is the single most important thing to understand, because the rumor mill has been louder than the facts.
If the deadline arrives and your PC is still running on the 2011 certificates, Windows will still boot, Windows Update will still work, and your PC will continue functioning normally.
What changes is that, in Microsoft’s own words, the device “will no longer be able to receive new security protections” for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, and mitigations for newly discovered boot-level vulnerabilities.
In plain English: Your PC becomes harder to protect over time. It’s protected against today’s known boot threats, but not necessarily against the ones that will be discovered next month or next year.
That’s a problem because bootkits operate underneath Windows and antivirus software. They run before anything else and can disable the security tools that would normally catch them.
The BlackLotus problem
If you want a concrete example of why boot-level security matters, look at BlackLotus.
BlackLotus is a UEFI bootkit that emerged on hacking forums in 2022 and was confirmed in the wild by researchers in early 2023. It exploited CVE-2022-21894, nicknamed “Baton Drop,” to bypass Secure Boot on fully patched Windows systems. Once installed, it could disable BitLocker, Hypervisor-Protected Code Integrity (HVCI), and Microsoft Defender before Windows fully loaded.
Microsoft addressed the underlying flaw in CVE-2023-24932, but fixing vulnerable boot managers safely is complicated. Revoking the wrong boot components can leave systems unbootable, which is why Microsoft has rolled out protections gradually over several years.
The 2026 certificate rollover is a planned lifecycle event (the 2011 certificates were always going to expire), but it also enables the broader Secure Boot hardening Microsoft has been doing in response to vulnerable boot managers and attacks such as BlackLotus.
With the new trust anchors in place, Microsoft can continue rolling out newer 2023-signed boot components and safely revoke vulnerable ones as new threats emerge. Devices that don’t make the transition may eventually miss those future protections.
How the rollout works
Microsoft is using a staged rollout designed to avoid breaking systems.
A scheduled Windows task runs roughly every 12 hours and applies the update in stages:
- Add the new Windows UEFI CA 2023 to the firmware’s signature database.
- If the old 2011 third-party certificate is still present, add the Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 alongside it.
- Add the new Microsoft Corporation KEK 2K CA 2023 key.
- Update the Windows Boot Manager to one signed by the new certificate. This step is deferred until the next natural reboot.
Microsoft’s IT pro guidance estimates the full process takes roughly 48 hours and one or more restarts to complete. Each step must succeed before the next one runs, so a device can sit partway through the sequence for a while if (for example) it’s waiting on a firmware update or a scheduled reboot.
For most home users, this happens silently in the background through normal cumulative updates.
Starting with the April 2026 Windows update, the Windows Security app includes updated Secure Boot status information under Device security that shows whether the new certificates have been applied successfully.

What could go wrong
Most systems will transition without problems, but there are some known trouble spots:
- Older PCs with outdated firmware. Some older UEFI firmware implementations don’t properly support the new certificates. These systems may require a BIOS or firmware update from the manufacturer before the transition can complete.
- PCs that bypassed Windows 11 requirements. If Secure Boot was disabled to install Windows 11 using unofficial workarounds, the new certificates cannot be applied correctly.
- Legacy BIOS / CSM systems. Devices running Legacy BIOS (or UEFI with Compatibility Support Module enabled) aren’t using Secure Boot at all, so they’re outside the scope of this update entirely.
- Custom firmware and weird configurations. Some custom or unusual firmware configurations may trigger a BitLocker recovery prompt after the Secure Boot variables change. Microsoft has been careful to note that BitLocker itself is not being disabled, but users should have their recovery keys handy just in case.
Windows Latest reported seeing update failures on thousands of PCs with outdated firmware during testing. Microsoft’s own guidance more broadly warns that firmware, platform, and OEM limitations can block the transition. In many cases, Windows Security will flag affected systems with yellow or red status warnings.
What home users should do
For most people, the advice is straightforward:
- Keep Windows fully up to date. Microsoft is rolling the new certificates out through normal Windows updates, and most home users won’t need to do anything beyond installing monthly updates.
- Check your Secure Boot status (the text, not just the color). Open Windows Security > Device security > Secure Boot. A green badge with the text “Secure Boot is on, preventing malicious software from loading when your device starts up.” is the all-clear. Microsoft warns that a green checkmark alone doesn’t confirm the new certificates have been applied.
- If your device is older, check for a BIOS/firmware update from your manufacturer. Some systems need them before the Secure Boot update can complete properly. This is especially important for PCs built before 2024.
- Don’t disable Secure Boot to “fix” something. Disabling Secure Boot is exactly the wrong response—it removes the protection entirely rather than updating it. Some game anti-cheat systems and older apps ask users to do this.
- Don’t panic about the new SecureBoot folder. Windows 11’s May 2026 cumulative update (KB5089549) creates a folder at
C:\Windows\SecureBootcontaining example PowerShell scripts intended for IT administrators. It’s not malware, it’s expected, and you don’t need to delete it. - Use up-to-date, real-time anti-malware protection that can detect threats at the OS level even if something does slip past Secure Boot.
What IT teams should do
If you manage a fleet, Microsoft has published extensive guidance and the work is more involved. The short version:
- Inventory your devices now. Pull the manufacturer, model, BIOS version and date, baseboard product, and Secure Boot status across the fleet. Microsoft provides a PowerShell sample script at
aka.ms/GetSecureBootthat surfaces the relevant registry keys and event IDs. - Watch Event IDs 1801 and 1808. Event ID 1808 confirms the new certificates are in place. Event ID 1801 means the device has not completed the update.
- Test before broad rollout. Microsoft recommends testing at least four devices per unique manufacturer/model/firmware combination. Some systems may need an OEM firmware update before they can accept the new certificates.
- Choose one deployment method per device. Use registry keys, Group Policy, WinCS command-line tools, or Intune/ConfigMgr scripts, but don’t mix methods on the same machine.
- Pay attention to PXE imaging and Hyper-V. SCCM/MECM PXE servers may need a re-signed
boot.wim, and Hyper-V hosts may need updating before new VMs are created with the 2023 KEK in the firmware template. - Document devices that can’t be updated. Older hardware without OEM firmware support may need to be replaced before the deadline or formally accepted as an exception with compensating controls. These devices will keep working, but they may miss future boot-level protections.
The bottom line
This is one of those security events that won’t generate a dramatic incident on June 24, 2026. Nothing visible will break that day.
The risk is what happens in the months and years after. Devices that fail to transition to the new trust chain may slowly fall behind on future boot-level protections as Microsoft continues responding to threats like BlackLotus and other bootkits.
For most home users, Windows Update will handle the transition automatically. Your main job is to keep your system updated and verify Secure Boot status before the deadlines arrive.
If your hardware is older, now is a good time to check whether your manufacturer still provides firmware updates—and whether your PC is ready for the next decade of Secure Boot protections.
“One of the best cybersecurity suites on the planet.”
According to CNET. Read their review →
3 easy-to-miss cybersecurity risks for small businesses
Small business owners should be sure to fix these three non-technical risks that require little cybersecurity expertise.
The post 3 easy-to-miss cybersecurity risks for small businesses appeared first on Security Boulevard.
How to Remove Objects from Video: AI Tools & Pro Tips (2026)
Apple patches WebKit bug that could let sites access your data
Apple has released a Background Security Improvement that silently fixes a WebKit vulnerability (CVE-2026-20643).
The post Apple patches WebKit bug that could let sites access your data appeared first on Security Boulevard.

