{"podcast":{"title":"Software Engineering Institute (SEI) Podcast Series","slug":"software-engineering-institute-sei-podcast-series-389154","podcast_index_feed_id":389154,"rss_url":"https://cmu-sei-podcasts.libsyn.com/rss","website_url":"https://www.sei.cmu.edu/publications/podcasts/index.cfm","image_url":"https://static.libsyn.com/p/assets/4/5/0/6/4506812e834bc5af16c3140a3186d450/5966_Libsyn.png","author":"Carnegie Mellon University Software Engineering Institute","episode_count":435,"summary":"The SEI Podcast Series presents conversations in software engineering, cybersecurity, and future technologies.","last_synced_at":"2026-08-01T02:18:38.616051+00:00","page_url":"https://stenobird.com/podcast/software-engineering-institute-sei-podcast-series-389154"},"episode":{"title":"Goal-Line Defense: A Tool to Discover and Mitigate UEFI Vulnerabilities","slug":"goal-line-defense-a-tool-to-discover-and-mitigate-uefi-vulnerabilities","published_at":"2026-04-15T13:26:00+00:00","page_url":"https://stenobird.com/podcast/software-engineering-institute-sei-podcast-series-389154/goal-line-defense-a-tool-to-discover-and-mitigate-uefi-vulnerabilities","show_page_url":"https://stenobird.com/podcast/software-engineering-institute-sei-podcast-series-389154","url":"https://cmu-sei-podcasts.libsyn.com/goal-line-defense-a-tool-to-discover-and-mitigate-uefi-vulnerabilities","audio_url":"https://traffic.libsyn.com/clean/secure/cmu-sei-podcasts/SEIP_02_19_SARVEPALLI.mp3?dest-id=762491","summary":"As recently as December 2025, the Carnegie Mellon University Software Engineering Institute (SEI's) CERT Coordination Center (CERT/CC) documented a UEFI-related vulnerability in certain motherboard models, illustrating that early-boot firmware behavior continues to present security challenges despite requiring local physical access to exploit. While CERT/CC reported seven UEFI vulnerabilities in 2025, that number remains small compared to reported vulnerabilities in other software . However, the consequences of a potential UEFI attack are often more serious given the extremely high privileges UEFI firmware possesses . In our latest SEI Podcast, Vijay Sarvepalli, a s enior i nformation s ecurity a rchitect specializing in v ulnerability and t hreat a nalysi s in CERT, sits down with Michael Winter, deputy technical director of threat analysis in CERT, to discuss research and mitigation of UEFI vulnerabilities and discuss a new tool, the CERT UEFI parser, an open source tool that uses program analysis to reveal the architecture of UEFI software, and explore this veiled source of vulnerabilities.","meta_description":"As recently as December 2025, the Carnegie Mellon University Software Engineering Institute (SEI's) CERT Coordination Center (CERT/CC) documented a UEFI-r…","key_points":[],"chapters":[],"topics":[],"duration_seconds":2479,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/software-engineering-institute-sei-podcast-series-389154/episodes/goal-line-defense-a-tool-to-discover-and-mitigate-uefi-vulnerabilities/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/software-engineering-institute-sei-podcast-series-389154/goal-line-defense-a-tool-to-discover-and-mitigate-uefi-vulnerabilities.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}