Just a bit more information. The secure boot fails because these updates replace the signed grubx64.efi with an unsigned version. I copied a signed grubx64.efi from a backup (overwriting the one from the updates), and now my secure boot is working correctly again.
Just a bit more information. The secure boot fails because these updates replace the signed grubx64.efi with an unsigned version. I copied a signed grubx64.efi from a backup (overwriting the one from the updates), and now my secure boot is working correctly again.