Posts

How to Update the Windows Boot Manager Certificate Before October 19, 2026

Image
  Microsoft is transitioning Windows devices away from older Secure Boot certificates issued in 2011. One of the most important dates for IT teams is October 19, 2026 , when the Microsoft Windows Production PCA 2011 certificate expires. This certificate is associated with signing the Windows boot loader, and Microsoft has introduced the Windows UEFI CA 2023 certificate as its replacement. For businesses managing dozens, hundreds, or thousands of Windows endpoints, this should not be treated as simply another Windows Update task. The challenge is determining which devices have already received the required Secure Boot certificate updates, which devices are blocked, whether firmware needs to be updated, and whether BitLocker or other security controls could complicate remediation . Microsoft says most devices receive Secure Boot certificate updates automatically, but some systems may require additional action, including OEM firmware updates. Microsoft recommends reviewing the de...

McKesson Data Exfiltration: Why Voice Phishing Target Healthcare Cloud Systems—and How to Protect Yours

Image
  A cybersecurity warning for hospitals, health systems, medical groups, pharmacies, healthcare SaaS providers, laboratories, and business associates A healthcare cyberattack does not always start with ransomware, malware, or a software vulnerability. Sometimes, it starts with a phone call . On August 25, 2026, McKesson discovered a cybersecurity incident affecting its information systems. In its SEC filing, the company said its investigation was in its early stages. McKesson subsequently confirmed unauthorized access to certain third-party applications and exfiltration of data associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. The incident has attracted additional attention because the ShinyHunters extortion group claimed responsibility and told reporters that its access began with voice phishing (vishing) against McKesson employees. The group claimed that compromised Okta SSO accounts were then used to access Sale...