Database/Firmware, BMC & network fabric
MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing private
Impact
The Money Message ransomware dump exposed MSI's firmware image-signing private keys for 57 products and Intel Boot Guard KM/BPM private keys for 116 products, reportedly touching Intel, Lenovo and Supermicro platforms. An attacker can sign a firmware image that the hardware root of trust accepts — Boot Guard is effectively void on affected silicon and the implant survives any OS reinstall
Who can reach it
Supply chain / local flash
What to do
There is no patch. Boot Guard keys are fused into the CPU at manufacture, so revocation is impossible on shipped hardware. The only response is to treat Boot Guard as non-authoritative on affected platforms and add an independent firmware-measurement/attestation layer
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.