Conversation

: Hey there is a update

Me: Let's install it!

: We just blocked a threat! We are \o/

Me: What threat?

: LoL not going to tell you 🙊

Me: Lets search for: "Defender ASR blocks Lenovo Bios Update"

Lenovo: To update the bios you need to temporary disable your rules

Me: FFS I guess we won't ever update this Bios throws hands in the air

2
1
0
@sassdawe "What threat?" -> The CVE-2025-47827 Secure Boot bypass is marked as exploited itw, but I'm not sure how that relates to Lenovo.
1
0
0

@buherator Defender doesn't like something about the bios updater but I can't see what because I am not an admin and can't UAC in the threat history view

1
1
0

@sassdawe this sounds like a similar theme to "our heuristic based EDR saw the license protection in this file as a threat and so it quarantined the entire install" chapter of the "your/our cybersecurity posture is based heavily on broken assumptions" guide to corporate tooling.

0
1
0