"You can be software 'secure' but firmware vulnerable."
"The release QA on the FirmwareUpdate bundles is concerning."
https://duo.com/assets/ebooks/Duo-Labs-The-Apple-of-Your-EFI...
"The advent of UEFI brought with it a far more 'modern' pre-boot environment and 'finally' put an end to the many years of legacy workarounds that had to be applied to the aging IBM BIOS 'standard', providing a common, uniform and higher-level platform to 'innovate' on."
"However, that uniformity and accessibility also opened the door to far more generic and useful pre-boot environment attack opportunities."