Business Wire

Binarly to Unveil “Broken Trust” Research: Firmware Bypass Chains, BMC Persistence, and EDR Evasion

16.1.2026 00:04:00 EET | Business Wire | Press release

Share

Binarly, the industry leader in software and firmware supply-chain security, today announced an upcoming DistrictCon presentation “Broken Trust: Firmware Bypass Chains, BMC Persistence, and EDR Evasion.” The session will detail how firmware-level attack chains observed in shipped enterprise devices can effectively undermine modern endpoint defenses, enabling stealthy compromise and long-lived persistence.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115834965/en/

Binarly Unveils Broken Trust Research: Firmware Bypass, BMC Persistence

In this presentation, the Binarly REsearch team will dismantle the assumption of hardware trust by presenting multiple real-world firmware bypass chains. Alex Matrosov and Fabio Pagani will provide a deep dive into the specific vulnerability classes and exploitation primitives that make these attacks reliable in practice. The team will also deliver a live demonstration compromising a fully patched system, illustrating how Endpoint Detection and Response (EDR) solutions can be blinded long before kernel drivers are even initialized.

The DistrictCon research will detail CVE-2025-12006 and CVE-2025-12007, two new high-impact Supermicro BMC vulnerabilities that enable attackers to install malicious firmware images and maintain persistent, difficult-to-remove implants inside server infrastructure. Binarly will outline the underlying technical root causes and discuss mitigation implications for platform vendors, enterprise defenders, and incident response teams.

Crucially, the research highlights the growing security debt in the rapidly expanding AI infrastructure sector. As organizations race to deploy high-density compute clusters to power generative AI, the reliance on bare-metal performance often outpaces hardware security verification. Binarly’s findings demonstrate how firmware-level persistence can survive standard server re-provisioning, potentially allowing attackers to breach tenant boundaries to access proprietary data and models.

“Firmware is the layer where trust is assumed, not continuously verified, and attackers take full advantage of that,” said Alex Matrosov, CEO and Head of Research at Binarly. “In Broken Trust, we’ll show how bypass chains we found in shipped firmware, including CVE-2025-12006 and CVE-2025-12007, make the case for supply-chain scale monitoring. Because in the real world, a small mistake in validation logic doesn’t stay small, it turns into persistence, and enterprise-wide risk.”

Binarly’s ongoing mission is to provide actionable intelligence and scalable transparency into software and firmware supply chains by helping organizations detect weaknesses early and reduce systemic risk across global device and software vendor ecosystems.

About Binarly

Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. Visit https://binarly.io for more information.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260115834965/en/

Contacts

Media Contact:
igor@binarly.io

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Prodalim Strengthens its Functional Platform to Enter the Fast-Growing Nutraceutical Market with the Acquisition of Sylvestre, a Market Leader in Botanical Extracts Based in Brazil12.3.2026 12:45:00 EET | Press release

Prodalim, a global leader in juice and specialty ingredients solutions, announced today the acquisition of Sylvestre, a leading Brazilian producer of botanicals and functional extracts addressing the nutraceutical market. Sylvestre’s existing owners and management team will remain with the company and support its integration into Prodalim’s platform. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260312584318/en/ Founded in 1992 in Brazil, Sylvestre is a trusted supplier of high-quality natural ingredients, specializing in botanical extracts, fruit powders, superfruits, teas, and unique functional plant-based solutions sourced from the rich and diverse Brazilian flora. With a portfolio of more than 200 natural ingredients, the company serves customers across the food, beverage, and nutraceutical industries, supporting wellness-oriented and health-driven applications. Leveraging Brazil’s rich biodiversity and advanced extract

Compass Pathways to Present at Stifel 2026 Virtual CNS Forum on March 18, 202612.3.2026 12:30:00 EET | Press release

Compass Pathways plc (Nasdaq: CMPS), a biotechnology company dedicated to accelerating patient access to evidence-based innovation in mental health, announced today that management will attend the Stifel 2026 Virtual CNS Forum, from March 17-18, 2026, and will participate in a fireside chat on March 18, 2026, at 10:30am ET. A live audio webcast of this event will be accessible from the “Events” page of the Investors section of the Compass website. A replay of the webcast will be accessible for 30 days following each event. About Compass Pathways Compass Pathways plc (Nasdaq: CMPS) is a biotechnology company dedicated to accelerating patient access to evidence-based innovation in mental health. We are motivated by the need to find better ways to help and empower people with serious mental health conditions who are not helped by existing treatments. We are pioneering a new paradigm for treating mental health conditions focused on rapid and durable responses through the development of our

WHOOP and Samuel Ross MBE Announce First Limited-Edition Collection Drop for PROJECT TERRAIN12.3.2026 12:00:00 EET | Press release

WHOOP, the human performance company, today announces that the first limited-edition collection drop of PROJECT TERRAIN, the multi-year collaboration between WHOOP and Samuel Ross MBE via SR_A, is now available for purchase. The debut collection introduces a technical garment system engineered for movement across environments - redefining the city as a modern training ground for daily performance. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260312513358/en/ WHOOP and Samuel Ross MBE Announce First Limited-Edition Collection Drop for PROJECT TERRAIN PROJECT TERRAIN marks a first for WHOOP, featuring reimagined executions of WHOOP bands, elevated WHOOP Body apparel, and the company’s first entry into technical outerwear. Designed as a unified system, each piece integrates the WHOOP device intentionally and visibly, transforming it from something worn discreetly into a central design element. Defined by SR_A’s architectural

NAFFCO Group and Verona Shelters Launch Strategic Joint Venture to Scale Civil and Military Shelter Production Globally12.3.2026 11:56:00 EET | Press release

NAFFCO Group has entered into a Joint Venture Agreement with Verona Shelters to form a strategic partnership dedicated to developing and manufacturing advanced civil defense and military shelter solutions in the United Arab Emirates. The partnership significantly expands global production capacity for protective shelter infrastructure at a time when governments and critical industries are strengthening resilience and civil preparedness. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260312010187/en/ Left: Verona Shelters: Eng. Shaikha Ali Rashed Al Kaabi, (MD UAE) and Mikko Lahtonen, (Executive Director Middle-East); Naffco Group: Eng. Khalid Al-Khatib (CEO); Mr. Ahmed Khalid Al-Khatib, (Group Managing Director); Mr.Ali Khalid Al-Khatib, (Group Managing Director); Ms.Nour Alyazji, (Business Development Director) The collaboration combines NAFFCO’s global leadership in safety engineering and large-scale manufacturing with Ver

Smiths Detection Celebrates Sale of its 2,000 th HI-SCAN 6040 CTiX 3D X-ray Scanner12.3.2026 11:00:00 EET | Press release

Smiths Detection, a global leader in threat detection and screening solutions, today announces the sale of its 2,000th HI-SCAN 6040 CTiX, an industry-leading 3D X-ray scanner with high-resolution 3D computed tomography images and intelligent AI-driven automatic detection capabilities. The HI-SCAN 6040 CTiX is deployed across over 100 airports in Europe, Asia-Pacific, the Middle East and the Americas. Operational experience across these regions has demonstrated consistent benefits for airports and passengers alike. Fewer false alarms mean faster, more reliable screening, and as threat profiles change, the technology keeps pace, strengthening security resilience over time. Meanwhile, in eligible locations, passengers no longer need to remove laptops or liquids from their bags, a small change that has a real impact on congestion at security checkpoints. Matt Clark, VP Commercial at Smiths Detection, said: “The sale of our 2,000th HI-SCAN 6040 CTiX is a powerful endorsement of the trust ai

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye