<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Firmware on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/firmware/</link><description>Recent content in Firmware on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 12 Jun 2025 13:05:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/firmware/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Surface Brick Flaw: Single Packet DoS Patched</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-surface-firmware-brick-vulnerability-single-packet-dos/</link><pubDate>Fri, 12 Jun 2026 13:05:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-surface-firmware-brick-vulnerability-single-packet-dos/</guid><description>A critical Surface firmware flaw allowed devices to be permanently bricked with one network packet. Microsoft has mostly patched the issue — here&amp;#39;s what to</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/12/microsoft-has-mostly-repaired-a-flaw-in-surface-hardware-that-allowed-unprotected-devices-to-be-bricked-by-a-single-packet/5253895">The Register — Security</a></p>
<hr>
<p>A vulnerability in Microsoft Surface hardware allowed an unpatched device to be permanently bricked by sending a single malicious network packet. The flaw was reportedly exposed inadvertently by Microsoft&rsquo;s own Copilot AI. Microsoft has largely addressed the issue, though the word &lsquo;mostly&rsquo; in the disclosure suggests remediation may not be complete across all affected hardware.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure all Surface devices in your estate have received the latest firmware updates immediately, and review endpoint management policies to confirm firmware patching is enforced through Intune or equivalent MDM. Given the DoS-via-single-packet nature of this flaw, also assess whether Surface devices are adequately isolated from untrusted network segments.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/12/microsoft-has-mostly-repaired-a-flaw-in-surface-hardware-that-allowed-unprotected-devices-to-be-bricked-by-a-single-packet/5253895">Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet</a></p>
]]></content:encoded></item></channel></rss>