Microsoft's Secure Boot, a security feature designed to protect Windows and Linux devices from firmware infections, has been compromised for over a decade. This revelation is particularly concerning given that Secure Boot was introduced to counter the threat of bootkits, malicious firmware that can persist even after an operating system reinstall or hard drive replacement. The vulnerability stems from the use of 'shims', secondary trust anchors signed by Microsoft, which were not revoked when vulnerabilities were discovered. This lapse allowed attackers to bypass Secure Boot using simple techniques, highlighting a critical flaw in the system's design and implementation. The complexity of Secure Boot's revocation process, which relies on version-based mechanisms like SBAT and Secure Boot SVN, has contributed to this issue. The discovery by ESET researchers underscores the need for a more robust and transparent approach to security, one that addresses the challenges posed by the intricate nature of modern firmware and boot processes. This incident serves as a stark reminder that even the most advanced security measures can be undermined by the intricacies of their own design, and that ongoing vigilance and innovation are essential to maintaining the integrity of our digital systems.