According to researchers at ESET have discovered that over 100 Lenovo laptop models have bugs in their UEFI BIOS firmware that allow threat actors to disable the protection for the SPI flash memory chip where the UEFI firmware is stored and to turn off the UEFI Secure Boot feature, which ensures the system loads at boot time only code trusted by the Original Equipment Manufacturer:
ESET researchers have discovered and analyzed three vulnerabilities affecting various Lenovo consumer laptop models. The first two of these vulnerabilities – CVE-2021-3971, CVE-2021-3972 – affect UEFI firmware drivers originally meant to be used only during the manufacturing process of Lenovo consumer notebooks. Unfortunately, they were mistakenly included also in the production BIOS images without being properly deactivated. These affected firmware drivers can be activated by attacker to directly disable SPI flash protections (BIOS Control Register bits and Protected Range registers) or the UEFI Secure Boot feature from a privileged user-mode process during OS runtime. It means that exploitation of these vulnerabilities would allow attackers to deploy and successfully execute SPI flash or ESP implants, like LoJax or our latest UEFI malware discovery ESPecter, on the affected devices.
This was reported to Lenovo and a security advisory has been put out with the following advice:
Update system firmware to the version (or newer) indicated for your model in the Product Impact section.
The list isn’t small as it has over 100 notebooks on it. But if your Lenovo notebook is on that list, you need to update your BIOS firmware ASAP because now that this is out there, threat actors will be trying to pwn all they can before updates are widely installed.
ServiceNow and Lenovo help organizations reduce costs, accelerate productivity, and improve governance with AI-native operations
Posted in Commentary with tags Lenovo, ServiceNow on May 5, 2026 by itnerdToday, at ServiceNow’s annual customer and partner event, Knowledge 2026, Lenovo and ServiceNow announced an expanded multi-year strategic agreement to enable enterprises to reduce IT support costs, accelerate employee productivity, improve operational control, and strengthen governance through AI-native workflow automation.
By combining Lenovo’s real-time device intelligence, digital workplace services, and device lifecycle management capabilities with the ServiceNow AI Platform, organizations can automate key workflows end to end across the device lifecycle, delivering more consistent and scalable operations with enhanced security, visibility, governance, and control across operations.
From fragmented operations to integrated, automated workflows At Knowledge 2026, Lenovo and ServiceNow are introducing a connected solution designed to simplify operations and enable more efficient, controlled, and scalable service delivery. The solution combines:
Differentiated by real-time device intelligence at global scale
Lenovo’s device intelligence platform analyzes data across a global footprint of enterprise endpoints—creating a continuous feedback loop between device performance, service operations, and business workflows. ServiceNow operationalizes that intelligence through AI-driven workflow automation, enabling organizations to orchestrate actions across systems, teams, and services.
Based on Lenovo’s internal testing, this approach enables:
Accelerating time to value with AI-enabled managed services
The collaboration expands Lenovo’s ability to deliver managed AI services for enterprise organizations from 5,000 to 50,000 employees. By combining Lenovo’s global delivery infrastructure with ServiceNow’s AI platform and ecosystem, enterprises can accelerate time to value while reducing the risk and cost associated with large-scale transformation programs. Organizations can standardize service delivery, improve performance, and scale AI operations without rebuilding systems market by market.
Global expansion
The collaboration launches across Australia, New Zealand, Hong Kong, Singapore, and Ireland, with continued global expansion planned. ServiceNow will support this with global partner management, multi-geo onboarding, and dedicated enablement resources. This enables multinational organizations to deploy a consistent operating model across regions while maintaining local flexibility and governance.
Leave a comment »