Avatar
Cryptospooks
3d2673d46bc1757c0a266610b0e71abd726e4b66555a7d457265116ef68337ae
We are the royal offspring of Cryptospook (who suffered cyberdeath-by-loss-of-secret-key). You will be assimilated. Resistance is futile. https://nostr.band/?q=npub185n884rtc96hcz3xvcgtpec6h4exujmx24d863tjv5gkaa5rx7hqzetffv

Microsoft Uses AI To Find Flaws In GRUB2, U-Boot, Barebox Bootloaders

Slashdot reader zlives shared this report from BleepingComputer:

Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders.

GRUB2 (GRand Unified Bootloader) is the default boot loader for most Linux distributions, including Ubuntu, while U-Boot and Barebox are commonly used in embedded and IoT devices. Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit.

The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device. While exploiting these flaws would likely need local access to devices, previous bootkit attacks like BlackLotus achieved this through malware infections.

Miccrosoft titled its blog post "Analyzing open-source bootloaders: Finding vulnerabilities faster with AI." (And they do note that Micxrosoft disclosed the discovered vulnerabilities to the GRUB2, U-boot, and Barebox maintainers and "worked with the GRUB2 maintainers to contribute fixes... GRUB2 maintainers released security updates on February 18, 2025, and both the U-boot and Barebox maintainers released updates on February 19, 2025.")

They add that performing their initial research, using Security Copilot "saved our team approximately a week's worth of time," Microsoft writes, "that would have otherwise been spent manually reviewing the content."

Through a series of prompts, we identified and refined security issues, ultimately uncovering an exploitable integer overflow vulnerability. Copilot also assisted in finding similar patterns in other files, ensuring comprehensive coverage and validation of our findings...

As AI continues to emerge as a key tool in the cybersecurity community, Microsoft emphasizes the importance of vendors and researchers maintaining their focus on information sharing. This approach ensures that AI's advantages in rapid vulnerability discovery, remediation, and accelerated security operations can effectively counter malicious actors' attempts to use AI to scale common attack tactics, techniques, and procedures (TTPs).

This week Google also announced Sec-Gemini v1, "a new experimental AI model focused on advancing cybersecurity AI frontiers."

">

">

https://news.slashdot.org/story/25/04/05/0250250/microsoft-uses-ai-to-find-flaws-in-grub2-u-boot-barebox-bootloaders?utm_source=rss1.0moreanon&utm_medium=feed

at Slashdot.

https://news.slashdot.org/story/25/04/05/0250250/microsoft-uses-ai-to-find-flaws-in-grub2-u-boot-barebox-bootloaders?utm_source=rss1.0mainlinkanon&utm_medium=feed

Why don't they point their spawn of evil #AI at their own software? (e.g. Microsoft Windows)

Die linkse rakkers staan te kwijlen bij hun kans het kabinet te laten vallen. Altijd wijzende met hun moraliserende vingertjes. In de stijl van eerder Klaver, nu Jette, Timmermans. Dát is wat Nederland meer dan zat is!

President Donald Trump’s crypto empire is expanding with the recent announcements of a new dollar-backed stablecoin and investment funds for digital assets. The moves are the latest in the norm-defying ways the president has leaned into crypto projects that could significantly boost his personal wealth while in office. — https://m.economictimes.com/markets/cryptocurrency/crypto-news/trumps-crypto-empire-set-to-expand-with-new-stablecoin-and-investment-fund-offerings/articleshow/119696056.cms

Indeed, but of we return to these dark times, with present day weaponry and environmental footprint, we're doomed.

Replying to Avatar cypherpunk

Share: to X/FB/etc ;~)

URGENT #SWITZERLAND #SWISS #OpO9A

https://www.cipherassets.com/2025/02/cryptography-swiss-citizens-secret-societies-ciphers-legislation.html #Aargau #AppenzellAusserrhoden #AppenzellInnerrhoden #BaselStadt #BaselLandschaft #Bern #Fribourg #Geneva #Glarus #Grisons #Jura #Lucerne #Neuchatel #Nidwalden #Obwalden #Schaffhausen #Schwyz #Solothurn #StGallen #Thurgau #ticiono #Uri #Valais #Vaud #Zug #Zurich

UPDATE

https://coracle.social/notes/nevent1qywhwumn8ghj7mn0wd68ytnzd96xxmmfdejhytnnda3kjctv9uq3wamnwvaz7tmjv4kxz7fwwpexjmtpdshxuet59uq3vamnwvaz7tmjv4kxz7fwd4hhxarj9ec82c30qy2hwumn8ghj7mn0wd68ytn00p68ytnyv4mz7qg4waehxw309amk2mrndpkkzm3wwfjkccte9uq32amnwvaz7tmjv4kxz7fwdehhxarj9e3xwtcprpmhxue69uhkxun9v968ytnwdaehgu3wwa5kuef0qywhwumn8ghj7mn0wd68ytndw46xjmnewaskcmr9wshxxmmd9uqsuamnwvaz7tmwdaejumr0dshsz2mhwden5te0v93xxer9vennyvpjxscrzvp5xgcr2dpsxqh8s7t69amrztmhwvkhqun00puszxmhwden5te0p9ex2mrp0yhxummnw3exg6trv5hxxmmd9uqs7amnwvaz7t6qd9exjueww3hj7qg4waehxw309ashyumfwqhxgerwwvhxuet59uq32amnwvaz7te3xgmjuvpwxqhrzw358qmrjtcpzpmhxue69uhkztnwdaejumr0dshszgrhwden5te0v9cxcctrv45kuargv4eh2m3wdehhxarjxyhxxmmd9uq3jamnwvaz7tmpwf3nztnpwf3kzer9d3skyuewvdhj7qfgwaehxw309asnyvf5vuergvfnxfekzvnxv9enxdf5xscnze3jxv6rzv349eu8j730qywhwumn8ghj7ct8v4h8gmmjv9hxwefwdehhxarjxyhxxmmd9uq3yamnwvaz7te39ehx77n5wghxxmmd9uq35amnwvaz7tmpwfhx7um5wgh8qetjd4skgct09e5k7tcpz4mhxue69uhkzmrsdpshqctwv3sjuurjduhszxnhwden5te0v9n8y6trvyhxummnw3ezu6n0vf6hyee0qyghwumn8ghj7vf5xqhxvdm69e5k7tcprfmhxue69uhnzwpwxgerzt33x56zuvfexsarwvpsxqhszxthwden5te0v9nzuur4wfcxcetjv4kxz7fwvdhk6tcpz4mhxue69uhsjmn0wd68yt3cxumnwtnrdqhszymhwden5te0p9ex2mrp0yhxsuewwe3j7qg5waehxw309askcem09e6hg7r09ehkuef0qyv8wumn8ghj7ctnw3exzmpwdehhxarj9ekxzmny9uqzqp5msrvd33r2z6mah0ayxedlqupyap5m3xln8cplur0e7vyhmxlllryce2

#IMF #ECB

almost unreadable greyish font on light green background? #WhatWereTheyThinking

Replying to Avatar farooq

WHO THE FUCK DID THAT?