Breaking
April 2, 2025

Microsoft has its AI-powered Security Copilot discover a whole host of previously unknown vulnerabilities | usagoldmines.com


  • Microsoft used Security Copilot to scan open source bootloaders for vulnerabilities
  • It discovered 20 new flaws in just a short time
  • Microsoft says the AI tool saved the company at least a week of work

Microsoft has revealed more on how its latest AI tools are proving useful spotting code vulnerabilities and more.

The company has published a new blog post detailing how it used Security Copilot (its AI-powered cybersecurity tool) to find almost two dozen vulnerabilities in different open-source bootloaders.

In total, Microsoft found 11 flaws in GRUB2, and nine more in U-Boot and Barebox.

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You’ll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)View Deal

Remote code execution risks

GRUB2 (GRand Unified Bootloader version 2) is a bootloader used in Linux and other Unix-like operating systems to manage the boot process and load the operating system.

U-Boot (Das U-Boot) and Barebox, on the other hand, are bootloaders primarily used in embedded systems. U-Boot is a widely adopted bootloader supporting various architectures, while Barebox is an alternative designed for faster boot times and easier maintenance.

The vulnerabilities span from integer and buffer overflows, to side-channel attacks and out-of-bounds read vulnerabilities.

Some of the flaws could be used to execute arbitrary code, Microsoft said, whereas others would need physical access to the vulnerable device, or would need the device to be infected with malware beforehand.

“While threat actors would likely require physical device access to exploit the U-boot or Barebox vulnerabilities, in the case of GRUB2, the vulnerabilities could further be exploited to bypass Secure Boot and install stealthy bootkits or potentially bypass other security mechanisms, such as BitLocker,” Microsoft said.

“The implications of installing such bootkits are significant, as this can grant threat actors complete control over the device, allowing them to control the boot process and operating system, compromise additional devices on the network, and pursue other malicious activities.”

“Furthermore, it could result in persistent malware that remains intact even after an operating system reinstallation or a hard drive replacement.”

All of the flaws now have a CVE assigned, and their severity is mostly “medium”, with one being rated “high” – 7.8/10.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best laptops 2025: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com

Best antivirus software 2025: Keep your PC safe from malware, spyware, and more | usagoldmines.com

Watch out! Don’t fall victim to these fake CAPTCHA scams on the web | usagoldmines.com

Firefox 137 finally gets tab groups, address bar improvements, and more | usagoldmines.com

Televes Innova Boss Mix review: Good TV reception, retro vibe | usagoldmines.com

Framework Laptop 12 pre-orders start April 9 | usagoldmines.com

Galaxy Z Fold 6 Gets Instant $300 Off, Plus $1,000 Off on Top With Trades Kellen | usagoldmines.com

All the Games Coming to the Nintendo Switch 2 Jake Peterson | usagoldmines.com

'Text Lens' Can Copy Any Text From Your Mac's Screen Pranay Parab | usagoldmines.com

Amazon Makes Last Minute Offer for TikTok as Ban Looms Juli Clover | usagoldmines.com

Apple Seeds First Betas of visionOS 2.5, tvOS 18.5, and watchOS 11.5 Juli Clover | usagoldmines.com

Apple Seeds First Beta of iOS 18.5 to Developers Juli Clover | usagoldmines.com

Apple Seeds First Beta of macOS Sequoia 15.5 Juli Clover | usagoldmines.com

Sony launches two new budget soundbars – one with Dolby Atmos and DTS:X, and one with big surround-s...

Hyrule Warriors: Age of Imprisonment sees Zelda take the lead, plus upgraded Switch 2 Editions bring...

11 things we learned from the Nintendo Switch 2 Direct, including the new Mario Kart, pricing for th...

Bad news, foldable fans – the rumored Samsung Galaxy tri-fold phone could be harder to get hold of t...

Apple TV+ has discovered the Fountain of Youth and you can jump in this May when the movie starts st...

The Nintendo Switch 2 Pro Controller has been revealed offering a bunch of improvements over its pre...

Deltarune gets surprise Chapter 3 and 4 release date at Nintendo Switch 2 Direct –and they're launch...

Nintendo Switch 2 mouse mode revealed: Joy Con 2 mouse function, how it works, and which games are c...

Some original Switch games will run better on Switch 2; some won’t run at all Andrew Cunningham | us...

A 32-bit processor made with an atomically thin semiconductor John Timmer | usagoldmines.com

DOGE staffer’s YouTube nickname accidentally revealed his teen hacking activity Ashley Belanger | us...

AI bots strain Wikimedia as bandwidth surges 50% Benj Edwards | usagoldmines.com

Galaxy S25 Edge Launch Now Reported for May Tim | usagoldmines.com

Everything We Know About the Switch 2's Design and Specs Jake Peterson | usagoldmines.com

This Nintendo Switch OLED Is $250 Right Now Pradershika Sharma | usagoldmines.com

Runway Says That Its Gen-4 AI Videos Are Now More Consistent David Nield | usagoldmines.com

Hollow Knight: Silksong was just shown at the Nintendo Switch 2 Direct with a 2025 launch window | ...

Dark mode for Google Photos is no longer exclusive to phones, as Google finally brings it to its web...

Microsoft reveals new tool to help with Windows 11 boot recovery crashes | usagoldmines.com

Donkey Kong Bananza announced at the Nintendo Switch 2 Direct | usagoldmines.com

Sony’s new TV lineup for 2025 doubles down on QD-OLED al.griffin@futurenet.com (Al Griffin) | usagol...

Say goodbye to disruptive OLED Care prompts on monitors - MSI will extend OLED Care 2.0 function to ...

Google warns North Korean spies are gaining positions in Western firms | usagoldmines.com

When it comes to security, public Wi-Fi could be a risky choice for commuters worldwide | usagoldmi...

Kirby Air Riders announced at the Switch 2 Direct as Nintendo throws in another racing game to the m...

Everything you need to know about bird flu Amber Dance, Knowable Magazine | usagoldmines.com

RIP Val Kilmer: Celebrating cult classic Real Genius is now a moral imperative Jennifer Ouellette | ...

Leak: More evidence of an Xbox handheld found in Windows 11 preview | usagoldmines.com

AVG Internet Security review: Reliable, budget-friendly antivirus software | usagoldmines.com

This 32-inch Samsung 4K monitor is only $220 right now | usagoldmines.com

This is not a drill: RTX 5070 is in stock at Best Buy, at MSRP | usagoldmines.com

Why I Pay for Kagi, the Ad-Free Google Search Alternative Pranay Parab | usagoldmines.com

Hulu and Paramount+ order a new Dexter prequel and Handmaid's Tale sequel, giving fans more killer t...

We finally know about the C button on the Nintendo Switch 2 – here’s what it does | usagoldmines.co...

Nintendo Switch 2 specs revealed, and yes, it will support 4K resolution - as well as a host of othe...

Nintendo Switch 2 is bringing back one of the Nintendo DS’s best features john-anthony.disotto@futur...

Thousands of PostgreSQL servers are being hijacked to mine crypto | usagoldmines.com

Mario Kart World – everything we know so far | usagoldmines.com

Tesla sales and production slumped heavily in Q1 2025 Jonathan M. Gitlin | usagoldmines.com

Best password managers 2025: Protect your online accounts | usagoldmines.com

Best free VPN for Android 2025: Which ones can you trust? | usagoldmines.com

Forget smart bulbs! This smart light switch is only $10 right now | usagoldmines.com

Beyond tariffs: 4 other ways phones, PCs and gadgets could suffer in 2025 | usagoldmines.com

MediaTek’s ‘Ultra’ Chromebook chips promise killer Minecraft power | usagoldmines.com

New Outlook: How to use offline mode and save emails locally | usagoldmines.com

How to move and delete apps on the Roku home screen | usagoldmines.com

AMD blames failing Ryzen 9000 chips on memory issues | usagoldmines.com

This Free App Brings Back the Windows 2000, XP, or Vista Taskbars Justin Pot | usagoldmines.com

PowerToys Now Converts Videos and Audio Too Justin Pot | usagoldmines.com

Get the 13-Inch M2 MacBook Air for the Low Price of $749 Mitchel Broussard | usagoldmines.com

Apple Hit With $5 Billion Class Action Lawsuit Over eBooks Availability Joe Rossignol | usagoldmines...

Millions of free VPN users have inadvertently sent their data to China chiara.castro@futurenet.com (...

Get ready, Tarnished! Elden Ring is coming to the Nintendo Switch 2 this year | usagoldmines.com

'We were old school': A Minecraft Movie's Jared Hess denies using AI to enhance his film adaptation ...

Palo Alto Networks gateways facing huge number of possible security attacks | usagoldmines.com

NYT Strands hints and answers for Thursday, April 3 (game #396) | usagoldmines.com

Quordle hints and answers for Thursday, April 3 (game #1165) | usagoldmines.com

NYT Connections hints and answers for Thursday, April 3 (game #662) | usagoldmines.com

The Samsung Galaxy Tab S10 FE launches with an iPad Air-rivaling screen and AI features galore axel....

While we wait for a Bloodborne remake or sequel, FromSoftware just announced The Duskbloods, a brand...

Unshittification: 3 tech companies that recently made my life… better Nate Anderson | usagoldmines.c...

Save $250 on this RTX 4060 gaming laptop with 32GB RAM | usagoldmines.com

6 reasons why wired headphones are better than wireless | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

How to Lock Down Your Phone When Crossing the U.S. Border Emily Long | usagoldmines.com

The 30 Best Original Shows Streaming on Max Right Now Ross Johnson | usagoldmines.com

Apple Reportedly Hasn't Given Up on Haptic Buttons for a Future iPhone Hartley Charlton | usagoldmin...

Google reveals better end-to-end encryption for Gmail business users | usagoldmines.com

The new Killswitch Nintendo Switch 2 case from Dbrand has loads of great features, and you can reser...

New tests cast a disappointing light on Nvidia’s RTX 5090 laptop GPU, suggesting that at today’s pri...

Mario Kart World officially revealed as a Nintendo Switch 2 exclusive | usagoldmines.com

David Fincher is making a Once Upon A Time in Hollywood sequel for Netflix with Brad Pitt set to ret...

The Nintendo Switch 2 officially launches this June | usagoldmines.com

2025 Audi RS e-tron GT: More range, more power, still drives like an Audi Jonathan M. Gitlin | usago...

Nintendo offers new Switch 2 details ahead of June 5 launch Kyle Orland | usagoldmines.com

Samsung Announces Galaxy Tab S10 FE and Tab S10 FE+, Start at $499 Tim | usagoldmines.com

You Can Grow a Mini Fruit Tree on Your Patio Amanda Blum | usagoldmines.com

New Plex Mobile App With Streamlined Interface Rolling Out to Users Tim Hardwick | usagoldmines.com

Google Messages is getting two big group chat upgrades – including a much-needed new snooze function...

Samsung Galaxy Ring 2 could be on the way with a powerful solid-state battery upgrade matt.evans@fut...

'Would have been nice to see': Daredevil: Born Again fans are upset about that fatal moment in episo...

Watch out, Apple and Garmin! UNA's sustainable, modular smartwatch is now live on Kickstarter stephe...

Epson's new UST 4K projector is mind-blowingly bright at up to 160 inches, but lacks a key HDR featu...

Your PC’s Windows install needs spring cleaning too. Here’s how to do it | usagoldmines.com

Does a VPN really provide 100% privacy? Here’s what you need to know | usagoldmines.com

New AirPods Max Firmware Unavailable Due to iOS 18.4 Bug, Apple Says Update 'Coming Soon' Tim Hardwi...

Why US third-party vendors need to act fast on DORA compliance | usagoldmines.com

Leave a Reply