UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Microsoft teaches AI to look for vulnerabilities in operating system bootloaders

Microsoft said that its specialists are actively using artificial intelligence for accelerated analysis of vulnerabilities in open bootloaders - critical components of operating systems that ensure their loading.

2 comments
Microsoft teaches AI to look for vulnerabilities in operating system bootloaders

Microsoft said that its specialists are actively using artificial intelligence for accelerated analysis of vulnerabilities in open bootloaders - critical components of operating systems that ensure their loading.

In its official blog, the company explained how Security Copilot helps detect potential threats faster than attackers could.

How it works

AI analyzes the source code of bootloaders and automatically finds potential security issues that could lead to exploits. Previously, this process was time-consuming and required significant human resources, but now the automated approach allows bugs to be found much faster.

Microsoft notes that this approach is already paying off: the AI ​​model has identified several critical vulnerabilities in popular downloaders, allowing developers to fix potential threats before they fall into the hands of hackers.

“With a number of clues, we identified a vulnerability in bootloaders that could be exploited by attackers. Copilot also helped find similar patterns in other files, providing comprehensive coverage and validation of our findings. This efficient process allowed us to confirm several additional vulnerabilities and extend our analysis to other bootloaders, such as U-boot and Barebox, which share code with GRUB2,” the company’s blog says.

Why is this important?

Installing such bootkits can have serious consequences, as they can give attackers complete control over a device. This allows them to interfere with the boot process and the operation of the operating system, compromise the security of other devices on the network, and perform other malicious actions.

"While attackers would likely need physical access to the device to exploit U-boot or Barebox vulnerabilities, in the case of GRUB2, these vulnerabilities could be used to bypass Secure Boot and install stealth bootkits or potentially bypass other security mechanisms such as BitLocker," Microsoft said.

Bootloaders are one of the most important parts of a system, as they are responsible for the correct startup of the operating system. If an attacker gains control of the bootloader, they can gain full access to the computer, bypass security systems, and install malware.

Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Microsoft adds AI-powered deep research tools to Copilot
Microsoft adds AI-powered deep research tools to Copilot
On the topic
Microsoft adds AI-powered deep research tools to Copilot
"The US may no longer be on the same team with us." Europe is considering abandoning American "clouds" from Google, Microsoft, and Amazon due to the actions of the Trump administration
“The US may not be on the same team with us anymore.” Europe is considering abandoning American “clouds” from Google, Microsoft and Amazon due to the actions of the Trump administration
On the topic
“The US may not be on the same team with us anymore.” Europe is considering abandoning American “clouds” from Google, Microsoft and Amazon due to the actions of the Trump administration
Microsoft has announced the release of a new AI voice assistant, Dragon Copilot. How it can be useful for doctors
Microsoft has announced the release of a new AI voice assistant, Dragon Copilot. How it can be useful for doctors
On the topic
Microsoft has announced the release of a new AI voice assistant, Dragon Copilot. How it can be useful for doctors
Also Read
Штучний інтелект DALL-E навчився домальовувати картини. Як це виглядає
Штучний інтелект DALL-E навчився домальовувати картини. Як це виглядає
Штучний інтелект DALL-E навчився домальовувати картини. Як це виглядає
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
Штучний інтелект почав озвучувати фільми на MEGOGO
Штучний інтелект почав озвучувати фільми на MEGOGO
Штучний інтелект почав озвучувати фільми на MEGOGO
3 comments

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel