Gigabyte releases BIOS updates to remove a backdoor in the firmware of over 270 motherboard models that could let hackers install malware when the PC restarts
Ionut Arghire / SecurityWeek :
Context & Ripple Effects
Eclypsium disclosed a week earlier that a firmware flaw in 271 Gigabyte motherboard models could let attackers drop malware that survives a reboot — the kind of persistence that lives below the operating system. Gigabyte's response, per the Eclypsium disclosure coverage, was a promise of a fix with a warning that problems could persist.
This BIOS update wave is the fulfillment of that promise, and it lands in a crowded field: MSI's 290+ boards shipping with a permissive default UEFI Secure Boot setting earlier this year, Dell's BIOSConnect remote-execution flaws, and Supermicro's virtual-USB-drive vulnerabilities all point at the same weak layer — vendor firmware that ships broadly and patches slowly.
First-order effects
- Owners of the affected 270+ Gigabyte boards must manually flash a BIOS update to remove the restart-persistent backdoor; unpatched machines remain exposed to firmware-level malware that antivirus tools typically cannot see.
Second-order effects
- Rivals like MSI and Supermicro, already carrying their own firmware disclosures, face pressure to audit and patch their UEFI code and to ship signed, automatic firmware updates rather than manual flash utilities.
Third-order effects
- If the pattern holds — Gigabyte, MSI, Dell, Supermicro, and the later Secure Boot key leak spanning Acer, Dell, Gigabyte, Intel, and Supermicro — firmware becomes a recurring supply-chain attack surface, pushing the industry toward mandatory signed firmware updates and third-party firmware auditing as standard practice.
The trend: Motherboard and PC firmware is consolidating into a systemic attack surface, with vendor patch cadence and Secure Boot integrity becoming the industry's next compliance battleground.