What can Framework learn from the CosmicStrand lesson? Implementing any new control / mitigation going forward?

Just kicking off this discussion if anyone is interested…

No idea what you’re talking about…

CosmicStrand is a UEFI rootkit. Because of this it can hide from OS virus scans and reinstall itself.

Here’s the Ars Technica write-up for those who are curious: Discovery of new UEFI rootkit exposes an ugly truth: The attacks are invisible to us | Ars Technica