Business Wire

Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion

15.1.2026 23:04:00 CET | Business Wire | Press release

Share

Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/

Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence

In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.

The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.

Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.

“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”

Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.

About Binarly

Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

OPEX® Corporation to Exhibit Advanced Warehouse Automation Solutions at LogiMAT 20264.3.2026 09:00:00 CET | Press release

OPEX® Corporation, a global leader in Next Generation Automation providing innovative solutions for warehouse, document and mail automation, will exhibit its latest advancements in warehouse automation at LogiMAT 2026. The world’s largest trade show for intralogistics solutions and process management, LogiMAT will be held March 24 through 26 at the Stuttgart Trade Fair Center in Germany. “Our team looks forward to being onsite at LogiMAT and showcasing several of our leading warehouse automation solutions,” said Alex Stevens, President, Warehouse Automation, OPEX. “We’re proud to deliver cutting-edge systems that help our clients transform how they conduct business, and we appreciate the vast opportunity LogiMAT provides to share our offerings and expertise with event attendees.” At LogiMAT Hall 5 ‒ Stand B25, OPEX will demonstrate Sure Sort® X with Xtract, its award-winning, automated pack-out and order takeaway system. The OPEX Booth will also feature a static display of the company’

Twilio and KPN Partnership Unlocks the Next Generation of Secure Business Messaging in the Netherlands, Powered by Google4.3.2026 09:00:00 CET | Press release

Milestone marks nationwide operator support for RCS Business Messaging, opening a scalable new market for brands Twilio (NYSE: TWLO), the customer engagement platform that drives real-time, personalised experiences for today’s leading brands, today announced at Mobile World Congress a partnership with KPN Netherlands (KPN) to enable nationwide Rich Communication Services (RCS) Business Messaging across all major mobile operators in the Netherlands, powered by Twilio and Google. RCS Business Messaging combines the simplicity and reach of sms with rich, interactive features such as verified sender identity, images, carousels and action buttons. This allows businesses to communicate in a more engaging, secure and measurable way, strengthening customer trust and improving the overall experience. Enabling nationwide RCS in the Netherlands With nation-wide coverage, KPN plays a central role in the country’s digital infrastructure. By joining the growing RCS ecosystem, this marks a defining m

SES Brings Satellite Connectivity to Refugees in Chad4.3.2026 08:50:00 CET | Press release

First Medium-Earth Orbit (MEO) deployment of the emergency.lu platform for refugees and their host communities’ use provides dependable broadband for humanitarian responders, classrooms and community connectivity centers SES, a space solutions company, is expanding humanitarian connectivity at the Farchana refugee settlement in Chad in cooperation with emergency.lu, the public-private partnership led by Luxembourg’s Ministry of Foreign and European Affairs, Defence, Development Cooperation and Foreign Trade and the UN Refugee Agency. In the framework of the Connectivity for Refugees initiative, the deployment uses SES’ O3b mPOWER satellite network to provide dependable, high-speed internet for humanitarian teams and essential services for refugees. This is the first emergency.lu deployment using O3b mPOWER satellites in Medium Earth Orbit (MEO), an expansion beyond the program’s previous use of geostationary (GEO) satellites for rapid disaster-response missions. It also marks a new app

Travel Smarter: Thales and Airalo Unlock a Seamless Global eSIM Experience4.3.2026 08:00:00 CET | Press release

Powered by Thales’ secure technology in eSIM connectivity management, this new solution ensures fast connection to local networks worldwide, delivering a smoother, more intuitive eSIM experience. For travellers, this means a simple eSIM installation for a seamless experience across 200+ destinations, making global connectivity as effortless and accessible as booking a flight or hotel. International travellers have increasingly relied on travel eSIMs to avoid high roaming fees, the hassle of searching for a local SIM card or relying on Wi-Fi hotspots. While this has improved connectivity access for millions, the process in the travel space remains cumbersome, still requiring manual configuration for each trip. By integrating Thales’ eSIM capabilities into its global platform, Airalo, the world’s largest travel eSIM platform, is further enhancing its technical architecture to provide its over 20 million users with a smoother travel experience. This press release features multimedia. View

Kao’s Laurier Launches New Brand Communication Initiative across Asia: Strengthening Global Integration as a Core Brand in Kao’s Asian Business4.3.2026 03:10:00 CET | Press release

Starting on International Women’s Day, March 8, Kao Corporation (TOKYO:4452) will launch new brand communication campaign in nine Asian countries and regions for its feminine sanitary product brand, Laurier, which is the core of its Asian business. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260303996141/en/ Laurier Campaign Key Visual Laurier aims to help create more supportive and understanding environments around menstruation, so that women can feel more at ease, both physically and emotionally, under the key message “Comfort, Made Together,” which will be implemented simultaneously across Asia. Kao aims to further develop Laurier as a global brand. Laurier, one of the core brands supporting Kao’s consumer care business in Asia, has been promoting globally integrated operations since 2023. Across all nine Asian countries and regions including Japan, Laurier has been working to unify product specifications and consolida

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye