Current estimates for new Secure Boot certificates are as far off as 2026. In the interim, users can only protect themselves by backing up BitLocker with their own PIN or disabling network access ...
BitLocker is enabled by default on newer Windows ... A permanent solution would be to revoke the certificates for vulnerable bootloaders, but the memory space reserved for this in the UEFI ...