WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Patch Awareness – NSA’s BlackLotus Mitigation Guide Addresses Recent Confusion Over Protections
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Patch Awareness – NSA’s BlackLotus Mitigation Guide Addresses Recent Confusion Over Protections

Author: April Zupan

Created: Tuesday, June 27, 2023 - 18:17

Categories: Cybersecurity, Federal & State Resources

The NSA has shared another Cybersecurity Information Sheet that addresses vulnerabilities in embedded computing functions. Earlier this month, it published joint guidance on Hardening Baseboard Management Controllers (BMCs). Last week, the NSA released the BlackLotus Mitigation Guide to help system administrators protect against BlackLotus, a vulnerability (CVE-2022-21894) that takes advantage of a boot loader flaw in supported versions of Microsoft Windows.

System administrators are encouraged to review the guidance carefully to confirm proper mitigations are in place.

The NSA guide provides an overview of recommended actions to detect and prevent malicious activities associated with BlackLotus. However, there has been some confusion since Microsoft’s addressing of the vulnerability in May’s Patch Tuesday. While Microsoft did provide new configuration options to protect against BlackLotus (and Baton Drop, a separate vulnerability), they are not enabled by default as system administrators are urged to verify devices are ready for the patch beforehand. This has created a situation where some organizations believe they are safe from BlackLotus just because they have applied the patch. The NSA urges organizations to confirm that these optional protections have been manually enabled for their devices, and carefully review the list of further mitigations and the FAQ. Read more at SC Magazine.

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar