Business Wire

Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion

16.1.2026 00:04:00 EET | Business Wire | Press release

Share

Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/

Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence

In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.

The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.

Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.

“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”

Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.

About Binarly

Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/

Contacts

Media Contact:
igor@binarly.io

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Owkin Creates New Spin out Waiv, Formerly Owkin Dx, With $33M Financing12.3.2026 15:30:00 EET | Press release

Owkin, the AI company on a mission to solve the complexity of biology, today announced the spin out of Waiv, formerly known as Owkin Dx. The move follows significant investor interest and positions Waiv to bring AI-powered precision testing for better identification of patients in the clinic and in clinical trials, to transform patient care. This follows on from the successful launch of Bioptimus, an Owkin incubated company, in February 2024. Waiv translates AI innovation into real-world clinical impact, developing tests that predict biomarkers and patient outcomes, including RlapsRisk BC for prognostic risk profiling. With multiple tests already in use in clinical settings, its deployment platform Destra, and collaborations with leading pharmaceutical companies, including MSD since 2023 for MSIntuit, Waiv is establishing itself as a leader in translational medical AI. Waiv leverages a decade of Owkin's foundational medical AI research, including access to an extensive patient data net

RQM+ Launches SMART Solutions Life Cycle Partnership Model12.3.2026 15:30:00 EET | Press release

RQM+, a leading MedTech CRO offering regulatory consulting, clinical trial, laboratory, and reimbursement services, today announced the launch of SMART Solutions, a life cycle partnership model designed to help medical device and diagnostics companies manage growing regulatory and development complexity. SMART Solutions introduces a strategy-led operating framework that unifies regulatory, quality, clinical, reimbursement, and laboratory expertise to support MedTech companies across the entire product life cycle to help reduce risk from early development through post-market. “MedTech companies are navigating unprecedented complexity as regulatory expectations evolve, product innovation accelerates, and post-market expectations are expanding,” said John Potthoff, Ph.D., chief executive officer of RQM+. “SMART Solutions moves beyond traditional consulting by providing an integrated life cycle partnership that helps sponsors gain earlier clarity, reduce risk, and execute complex programs

Andersen Consulting Broadens Capabilities Through Collaboration with Acumen Learning12.3.2026 15:30:00 EET | Press release

Andersen Consulting adds depth to its platform through a Collaboration Agreement with Acumen Learning, a U.S.-based firm specializing in business and financial acumen training for leadership development and sales performance. Founded in 2002, Acumen Learning works with Fortune 500 companies to enhance financial literacy, strategic thinking, and decision-making across all levels. Drawing from the principles in their best-selling books “Seeing the Big Picture” and “Business Acumen for Sales Success,” their programs equip leaders and teams to align decisions with corporate strategy, drive performance, and strengthen client relationships. Tailored for industries such as healthcare, energy, and technology, Acumen Learning empowers professionals to translate business knowledge into actionable impact. “At Acumen Learning, our mission is to empower individuals by creating business-savvy professionals who excel in their careers,” said CEO of Acumen Learning Kevin Cope. “Our courses pair practic

Cryptio Raises $45m Series B as Digital Assets Move Into Regulated Financial Markets12.3.2026 15:06:00 EET | Press release

Cryptio, a leader in financial data transformation and enterprise resource planning (ERP) applications for regulated digital assets, announced today a $45 million Series B funding round co-led by BlackFin Capital Partners and Sentinel Global, with participation from 1kx, Alven, BlueYard Capital and Ledger Cathay Capital. Banks, exchanges, asset managers, including Société Générale’s SG Forge, Circle, Gemini, and Securitize rely on Cryptio to ensure financial integrity across their digital assets businesses. Existing ERP systems fall short for digital assets Traditional ERP and accounting systems were not designed for blockchain-native assets, real-time reporting, or modern custody frameworks. As regulated financial institutions expand into stablecoins, tokenized securities and other on-chain instruments, these limitations create material operational and reporting challenges. Cryptio was built to address this gap. The company’s data platform standardizes and reconciles both on-chain and

HyperLight Introduces 145 GHz Reference Modulators to Enable 448Gbps per Lane Datacom and 260GBaud Telecom Development12.3.2026 15:03:00 EET | Press release

HyperLight Corporation, creator of the TFLN Chiplet™ platform, today announced the release of its 145 GHz Packaged Intensity Modulator (IM), expanding the company‘s high-speed modulator portfolio. The new device is designed for ultra-wide modulation bandwidth, high signal fidelity, and stable operation control, enabling 448 Gbps per lane intensity-modulated-direct-detection (IMDD), 260 GBaud coherent links, and broadband RF photonics systems. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260312319685/en/ Fig. 1: HyperLight’s 145 GHz intensity modulator for 448Gbps per lane IMDD and 260GBaud coherent applications, with operational electro-optical bandwidth >145GHz, stable bias control, 0.8 mm-connector; available in O-, C-, and L-bands. As symbol rates and analog bandwidth requirements continue to rise across data center interconnects, AI-driven photonics infrastructure, and laboratory test environments, system architects in

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye