Microsoft has recently begun replacing expiring Secure Boot certificates on eligible Windows 11 systems running 24H2 and 25H2 ...
Make sure you've updated before the deadline.
ASUS releases BIOS 2102 with AGESA 1.3.0.0a to fix BitLocker recovery loop issues on AM5 600 and 800 series motherboards.
Microsoft confirms systems without updated Secure Boot certificates will boot normally but lose some security protections.
So... my Asus mobo (ROG Strix Z390-E Gaming) is from 2018, and while the code Andrew provided for PowerShell shows I'm OK for the new cert, I get "False" for Default ...