Windows Clarifies Secure Boot and Certificate Chaos: What Expires, When, and What Happens Next
Back in February, we began discussing the implications of Secure Boot, and at the time, it seemed far less complex than what Microsoft has now laid out. The conversation revolved around certificates expiring in June 2026, the potential need for a BIOS update, and the necessity of keeping Windo
Back in February, we began discussing the implications of Secure Boot, and at the time, it seemed far less complex than what Microsoft has now laid out. The conversation revolved around certificates expiring in June 2026, the potential need for a BIOS update, and the necessity of keeping Windows up-to-date for Secure Boot. This fundamental information remains accurate, but now Microsoft (and ASUS) have provided more concrete details, including specific dates, visible system statuses, and real-world scenarios that were previously unclear regarding Secure Boot.
To elaborate on what was previously stated would be an understatement, as the company has introduced three changes and two clarifications that are crucial to understand if you are affected, to grasp the direction things are heading.
Microsoft Defines Windows' New Secure Boot and Its Certificates
The first notable update compared to February concerns the timeline and the precise separation of certificates, as Microsoft is not treating this as a single deadline. The Microsoft Corporation KEK CA 2011 expires in June 2026 and will be replaced by Microsoft Corporation KEK 2K CA 2023.
Meanwhile, the Microsoft Windows Production PCA 2011 expires in October 2026 and will be succeeded by Windows UEFI CA 2023. The focus is no longer just on saying "certificates are expiring," but rather on identifying which specific element is expiring, when, and which new credential will take its place within the renowned Secure Boot process, a welcome detail for system administrators.
The second new development is that Microsoft has begun displaying this information within Windows Security. Phase 1 commenced on April 8, 2026, for various versions of Windows 11 and Windows Server 2025, and on April 14, 2026, for Windows 10 and certain Windows Server editions. This stage will feature green and yellow indicators. In contrast, Phase 2 will arrive on May 16, 2026, for parts of Windows 11 and on May 13, 2026, for Windows 10 and several Windows Server versions, introducing notifications and red status indicators for the most critical situations. In essence, this issue is no longer hidden in technical documents; it is becoming visible within the system's own interface, allowing anyone to identify its status.
ASUS Has Officially Spoken to Assist Users
The third piece of news somewhat reduces the alarm initially associated with the BIOS. ASUS explains that if Windows Update is enabled and Secure Boot is active, compatible systems will automatically download and install the new certificates and the new Boot Manager. Furthermore, they indicate that the phased rollout began in 2024 and is expected to be completed before June 2026. In other words, there is no universal need to manually update the BIOS on all PCs and laptops, although some may require additional firmware.
Adding to this are the two important clarifications mentioned earlier, which provide further perspective on the situation. The first is that if a system does not receive the new certificates in time, it will continue to boot normally and will still be able to install regular Windows updates.
However, it will cease to receive new early boot phase protections, including Boot Manager updates, Secure Boot databases, revocation lists, and mitigations against low-level vulnerabilities such as certificates. The second point is more delicate: ASUS already documents that if Windows has used a Boot Manager signed in 2023 and then the firmware is reset to factory defaults without including the Windows UEFI CA 2023, Secure Boot may prevent the system from booting.
This is the real difference compared to what we saw in February: we are no longer talking about a general warning but a much more defined picture of what expires, when it happens, and what the consequences might be afterward.
Fresh materials — Technology News

Google Pixel Devices Hit by Nightmare Bug: September Update Locks Out Some Users
Updating your phone should be a simple process: install, restart, and continue. But imagine completing the update, entering your usual unlock pattern, and the phone not even letting you finish it. Your photos and messages remain, but you're locked out. This is the predicament some Google Pixel

NVIDIA GeForce RTX 4090 Founders Edition Loses Part of Its Heatsink After Three Years
A NVIDIA GeForce RTX 4090 Founders Edition has presented an unusual problem, not with its power connector, but with its heatsink. This incident is unique, as a portion of the graphics card's massive heatsink literally detached while its owner was moving the computer. This wasn't a decorative c

Russian Missiles Strike Infrastructure of 1337x, Second Largest Torrent Tracker, Hitting Piracy
Russian missile attacks have damaged infrastructure belonging to popular torrent trackers like 1337x. Between September 23 and 27, 2026, Russia conducted strikes targeting data centers and communication facilities in Kyiv. These attacks temporarily disrupted internet access for approximately 1

NVIDIA, Google, and AMD Poised to Control 85% of HBM Memory Demand by 2027
The "you'll own nothing and be happy" meme is finding a parallel in hardware, specifically memory. NVIDIA, Google, and AMD are set to command 85.4% of the global High Bandwidth Memory (HBM) demand by 2027, according to Morgan Stanley estimates. These three buyers will largely dictate the pace

Windows 11 26H2 Reduces RAM Consumption by Up to 2 GB, But 8 GB Machines Still Struggle
Windows 11 26H2 is rolling out optimizations for RAM management. Some users report a noticeable decrease in RAM usage after installing this update, with certain systems showing a reduction of up to 2 GB compared to Windows 11 25H2 upon startup. However, initial findings suggest this improvemen

RTX 5090 fails with DLSS 5 after 48 hours for Chinese streamer
NVIDIA's RTX series introduced Tensor Cores, enabling technologies like DLSS. Early DLSS versions offered a noticeable drop in image quality compared to native resolution. DLSS 2 brought significant improvements, and DLSS 3 achieved parity or even superiority over native rendering. DLSS 4 cont