Close Menu
  • Home
  • Stock
  • Parenting
  • Personal
  • Fashion & Beauty
  • Finance & Business
  • Marketing
  • Health & Fitness
  • Tech & Gadgets
  • Travel & Adventure

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 longevity mistakes that catch up to women after menopause

agosto 24, 2026

‘Lust-free’ gyms say they’re safe spaces for Christian men

agosto 21, 2026

Experimental ‘exercise pill’ may reduce appetite and mimic physical activity

agosto 21, 2026
Facebook X (Twitter) Instagram
  • Home
  • Contact us
  • DMCA
  • Política de Privacidad
  • Publicidad en DD Noticias
  • Sobre Nosotros
  • Términos y Condiciones
Facebook X (Twitter) Instagram
DD Noticias: Tu fuente de inspiración diariaDD Noticias: Tu fuente de inspiración diaria
  • Home
  • Stock
  • Parenting
  • Personal
  • Fashion & Beauty
  • Finance & Business
  • Marketing
  • Health & Fitness
  • Tech & Gadgets
  • Travel & Adventure
DD Noticias: Tu fuente de inspiración diariaDD Noticias: Tu fuente de inspiración diaria
Home » Microsoft Uses Security Copilot to Identify 20 Flaws in Open-Source Bootloaders
Technology & Gadgets

Microsoft Uses Security Copilot to Identify 20 Flaws in Open-Source Bootloaders

Jane AustenBy Jane Austenabril 3, 2025No hay comentarios2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Microsoft Uses Security Copilot to Identify 20 Flaws in Open-Source Bootloaders
Share
Facebook Twitter LinkedIn Pinterest Email


Microsoft Security Copilot, an artificial intelligence (AI) cybersecurity tool, was used to discover several previously unknown vulnerabilities in open-source bootloaders. The Redmond-based tech giant recently revealed a list of the security flaws discovered in three commonly used bootloaders. One of the bootloaders is the default for many Linux-based systems, while the other two are typically used for embedded systems and Internet of Things (IoT) devices. Notably, Microsoft has informed the bootloader maintainers about the exploits, and they have released security updates to fix them.

Microsoft Showcases Its AI System’s Vulnerability Discovery Process

In a blog post, Microsoft detailed the discovery process and extent of risk with these vulnerabilities. The company used Security Copilot, an AI-powered security analysis tool that can assist in protecting organisations from threat actors as well as discovering security flaws. These vulnerabilities were detected in GRand Unified Bootloader (GRUB2), U-Boot, and Barebox, commonly used bootloaders for operating systems and devices.

GRUB2 is the default bootloader for many Linux-based systems, whereas U-Boot and Barebox are generally seen in embedded systems and IoT devices. Notably, a bootloader is a small program that runs before the operating system (OS) starts. It is responsible for loading the OS into memory and initiating the boot process.

By using AI, Microsoft Threat Intelligence discovered 11 vulnerabilities in GRUB2, including issues like integer overflows, buffer overflows, and a cryptographic side-channel flaw. These security flaws could allow threat actors to bypass the Unified Extensible Firmware Interface (UEFI) Secure Boot, which is designed to prevent unauthorised code from running during the boot process.

Security Copilot also discovered nine vulnerabilities in U-Boot and Barebox. These were primarily buffer overflows that affected file systems such as SquashFS, EXT4, CramFS, JFFS2, and symlinks. Notably, the threat actor would need to have physical access to the device to exploit these flaws, however, the security risk still exists.

In the case of GRUB2, Microsoft explained that the vulnerabilities could be exploited by attackers to install stealthy bootkits remotely. This is concerning, as such bootkits can persist even after reinstalling the operating system or replacing the hard drive.

The teams behind GRUB2, U-Boot, and Barebox have already released security updates in February to address these vulnerabilities. Users are advised to update their systems to the latest versions to protect themselves from potential cyberattacks.

Affiliate links may be automatically generated – see our ethics statement for details.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Jane Austen
  • Website

Related Posts

Bitcoin Core v30 allenta OP_RETURN: Alcuni miner S19 affrontano una pressione di booster

noviembre 17, 2025

Bitcoin Core v30: No es una actualización — es presionar el 「booster de eliminación de mineros」

noviembre 17, 2025

Pika Labs Launches Social AI Video App on iOS, Unveils New Audio-Driven Video Generation AI Model

agosto 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Fast fashion pioneer Forever 21 files for bankruptcy — again

marzo 18, 2025

Dow gains 350 points as stocks climb for 2nd day after S&P 500 enters correction

marzo 18, 2025

Yellow Creditors Have Own Plan to Share Trucker’s $550 Million

marzo 18, 2025

Alphabet in Talks to Buy Startup Wiz for $30 Billion, WSJ Says

marzo 18, 2025
Top Reviews
DD Noticias: Tu fuente de inspiración diaria
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • Contact us
  • DMCA
  • Política de Privacidad
  • Publicidad en DD Noticias
  • Sobre Nosotros
  • Términos y Condiciones
© 2026 ddnoticias. Designed by ddnoticias.

Type above and press Enter to search. Press Esc to cancel.