I know I've had a bios update in the past month or two with updated key revocation lists for secure boot. OEMs generally don't update their support binaries, they see no reason to. By your screenshot ...
A new Steam beta update is making it easier for gamers to check the status of Secure Boot and TPM on their gaming PC, must-have requirements for anti-cheat in plenty ...