@fribbledom To be fair, this is nothing Microsoft specific, some (Enterprise) Distros will start to ship these as well. These should be the official upstream lists from: uefi.org/revocationlistfile

It's mainly an oversight of these distros to not get newer signatures. (Unless you point out, that Microsoft denies these to them or didn't respond in time, which is not completely unexpected.)