Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion
16.1.2026 00:04:00 EET | Business Wire | Press release
Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/
Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence
In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.
The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.
Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.
“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”
Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.
About Binarly
Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/
Contacts
Media Contact:
igor@binarly.io
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
NTT DATA Announces Intent to Acquire WinWire to Scale Enterprise AI Adoption and Accelerate Industry Transformation with Microsoft15.5.2026 17:00:00 EEST | Press release
NTT DATA, a global leader in AI, digital business and IT services, today announced it has signed a definitive agreement to acquire WinWire,an award-winning Microsoft partner specializing in Agentic AI, AI on Azure, data engineering and cloud-native development as foundational capabilities for enterprise AI. The acquisition strengthens NTT DATA’s position as a trusted partner to help organizations move beyond experimentation to operationalize AI at scale. The acquisition further advances NTT DATA’s enterprise AI strategy as demand accelerates for AI-driven, cloud-native transformation. By expanding capabilities across data platforms, agentic AI and modern applications, NTT DATA is sharpening its ability to deliver production-ready AI solutions aligned to industry needs, reinforcing its leadership as Microsoft’s Global System Integrator (GSI) Growth Champion Partner of the Year. Upon closing, WinWire will add more than 1,000 skilled Azure engineers and Microsoft specialists to NTT DATA,
Experian Expands Agent Trust Partner Ecosystem with Akamai to Advance Trusted AI Driven Commerce15.5.2026 16:00:00 EEST | Press release
Experian today announced that Akamai Technologies has joined its growing partner ecosystem, designed to further advance secure, trusted AI driven commerce through the Experian Agent Trust™ framework, alongside partner Skyfire supporting emerging payment innovation. As AI agents begin to search, decide, and transact autonomously, they introduce a fundamental challenge for businesses: how to trust an action when it is no longer directly initiated by a human. Without a verified connection between humans and AI agents, autonomous commerce introduces new risks in fraud, misrepresentation, and unauthorized transactions. Experian Agent Trust is designed to address this challenge by establishing identity, accountability, and trust in agent driven interactions. “Trust, security, and performance must scale alongside the growing role of AI agents in digital commerce,” said Kathleen Peters, Chief Innovation Officer at Experian. “Agentic commerce will not scale without trust. By adding Akamai to ou
The LYCRA Company and Dukane Advance Ultrasonic Bonding for Nonwovens at INDEX™ 2615.5.2026 15:00:00 EEST | Press release
The LYCRA Company, a global leader in innovative and sustainable fiber solutions for the personal care industry, and Dukane, a manufacturer of ultrasonic bonding technologies for the hygiene and nonwovens market, are showcasing their latest co-developed advances in ultrasonic bonding at INDEX™ 26, taking place in Geneva, Switzerland, from May 19–22. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260515514441/en/ Join The LYCRA Company and Dukane at INDEX™ 26 in Geneva, as they showcase their latest advances in ultrasonic bonding for nonwovens, including new LYCRA FUSION™ fiber for personal care that delivers superior snapback. Since 2014, both companies have collaborated to advance ultrasonic bonding solutions that help diaper manufacturers improve product softness, fit, and performance while reducing energy consumption, material waste, and maintenance costs. Ultrasonic bonding creates bonded channels between two layers of n
Vecima to Highlight Next-Generation 50G-PON, DOCSIS® 4.0 vCMTS, AI & Automation, and Monetizable Streaming at ANGA COM 202615.5.2026 14:45:00 EEST | Press release
Vecima Networks Inc. (TSX: VCM) will highlight its leadership in next-generation broadband at ANGA COM 2026, showcasing AI-powered network operations, cloud-native DOCSIS® 4.0 access, and scalable fiber solutions. Anchored by the Entra® vCMTS platform, Automation, and All-PON™ innovations, Vecima is enabling operators to automate operations, improve reliability, and accelerate the evolution to converged cable and fiber networks. Delivering on Next-Generation PON With Entra All-PON™, Vecima is enabling future-ready fiber networks with a straightforward migration path from today’s 10G technologies to 50G-PON, ensuring long-term scalability and investment protection. The new Entra EPS1650 All-PON Shelf supports 50G-PON, XGS-PON, 10G-EPON, GPON, and EPON services. As a follow-on to Vecima's industry-first demonstration of a single port supporting 50G ITU PON and 10G-EPON in a Remote OLT, the EPS1650 brings that same single-port investment-protection path to GPON and XGS-PON operators in a
REPLY: The Board of Directors Approves the Quarterly Report Dated 31 March 202615.5.2026 14:38:00 EEST | Press release
Today, the Board of Directors of Reply S.p.A. [EXM, STAR: REY] approved the results as at 31 March 2026. Since the beginning of the year, the Group has recorded a consolidated revenues amounting to €645.0 million, an increase of 6.2% compared to the corresponding data for 2025. All indicators are positive for the period. In the first quarter of 2026 the consolidated EBITDA stood at €112.0 million compared to €105.3 million in 2025, equal to 17.4% of the turnover. EBIT, from January to March, was €95.1 million (€88.7 million in 2025) and is equal to 14.7% of the turnover. The profit before tax, from January to March, was €99.8 million (€86.9 million in 2025), equal to 15.5% of the turnover. The net financial position of the Group on 31 March 2026 is positive at €643 million. The net financial position on 31 December 2025 was positive for €467.6 million. “The results we have presented - said Mario Rizzante, Chairman of Reply - confirm the soundness of the path we have undertaken in recen
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom