I've just been reading through the new /doc/about/warnings/.
It includes "No operating system can protect against BIOS and firmware
attacks" and explains why that is, followed by a suggestion how to
reduce that issue.
What I'm missing is a hint to use Libre/Coreboot as an option to prevent
some of such attacks. (at least that is my assumption)
https://tails.boum.org/doc/about/warnings/