Home ยป Unveiling Security Copilot by Microsoft: Unearthing Vulnerabilities in GRUB2 Code

Unveiling Security Copilot by Microsoft: Unearthing Vulnerabilities in GRUB2 Code

Microsoft Security Copilot is an AI tool designed to identify security vulnerabilities since 2023. Recently, Microsoft showcased the effectiveness of Security Copilot in pinpointing real vulnerabilities.

In this latest round, vulnerabilities were discovered in open-source bootloader software like GRUB2, commonly used in Linux, U-boot, Barebox (both prevalent in embedded operating systems). Microsoft employed their Threat Intelligence team to instruct Security Copilot to search for integer overflow vulnerabilities within the bootloader software code. This approach replaced manual code reading by humans.

Microsoft’s team uncovered 11 vulnerabilities in GRUB2 and found interconnected vulnerabilities due to code sharing between U-boot and Barebox. They promptly shared this information with the software development team, who released patches in mid-February 2025.

Source: Microsoft, Bleeping Computer

TLDR: Microsoft Security Copilot AI identified integer overflow vulnerabilities in GRUB2’s code.

More Reading

Post navigation

Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Apple Releases macOS Sonoma 14.4, watchOS 10.4, and Software Updates Within Its Ecosystem

Apple releases incremental updates iOS 17.2.1 and macOS Sonoma 14.2.1 concluding the year

Enhancing Work Efficiency with Microsoft Security Copilot’s Agentic AI Features, Supported by Partner Agents.