Blue data streams highlighting expiring boot keys and router botnet attacks.

Daily Cybersecurity News - June 21, 2026

Windows Linux Boot Keys Expiring Soon

Boot security keys for Windows and Linux machines will start expiring on June 24. Systems relying on the old certificates will lose trusted boot chain validation.

The keys sign the initial bootloaders and firmware components. Once expired, loaders fail signature checks on affected hardware. No CVE or CVSS score applies since this is certificate lifecycle, not a code flaw.

Affects any device using the 2011-era Microsoft certificates for UEFI Secure Boot, including the Microsoft UEFI CA 2011 that signs the Linux shim. Includes older Windows 10/11 builds and many Linux distros with default keys.

Windows 11 24H2 already ships the replacement keys.

Source: Wired

A new botnet called AryStinger has turned thousands of outdated D-Link routers into proxies for malicious traffic.

It exploits known vulnerabilities in older firmware to gain access, then installs custom malware that routes attacker traffic through the devices. The campaign has hit more than 4,000 routers worldwide.

The malware is previously undocumented and built for intrusion reconnaissance, including scanning, service mapping, and acting as an attack springboard, rather than the usual DDoS or cryptomining seen in router botnets. Proxying is one of its capabilities.

The infection volume grew steadily over several months with minimal infrastructure changes.