WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Patch Awareness – NSA’s BlackLotus Mitigation Guide Addresses Recent Confusion Over Protections
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Patch Awareness – NSA’s BlackLotus Mitigation Guide Addresses Recent Confusion Over Protections

Author: April Zupan

Created: Tuesday, June 27, 2023 - 18:17

Categories: Cybersecurity, Federal & State Resources

The NSA has shared another Cybersecurity Information Sheet that addresses vulnerabilities in embedded computing functions. Earlier this month, it published joint guidance on Hardening Baseboard Management Controllers (BMCs). Last week, the NSA released the BlackLotus Mitigation Guide to help system administrators protect against BlackLotus, a vulnerability (CVE-2022-21894) that takes advantage of a boot loader flaw in supported versions of Microsoft Windows.

System administrators are encouraged to review the guidance carefully to confirm proper mitigations are in place.

The NSA guide provides an overview of recommended actions to detect and prevent malicious activities associated with BlackLotus. However, there has been some confusion since Microsoft’s addressing of the vulnerability in May’s Patch Tuesday. While Microsoft did provide new configuration options to protect against BlackLotus (and Baton Drop, a separate vulnerability), they are not enabled by default as system administrators are urged to verify devices are ready for the patch beforehand. This has created a situation where some organizations believe they are safe from BlackLotus just because they have applied the patch. The NSA urges organizations to confirm that these optional protections have been manually enabled for their devices, and carefully review the list of further mitigations and the FAQ. Read more at SC Magazine.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar