Microsoft used Security Copilot with artificial intelligence to discover previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders . GRUB2 (GRand Unified Bootloader) is the default bootloader for most Linux distributions, while U-Boot and Barebox are commonly used in embedded and IoT devices .

Through AI Security Copilot, the company discovered eleven vulnerabilities in GRUB2 and nine in U-Boot and Barebox. These bugs affect devices based on UEFI Secure Boot and, if the right conditions are met, attackers can bypass security protections and execute (potentially malicious) code on the device.
See also: NCSC urges immediate patching of Next.js vulnerability
In most cases, local access to devices to exploit vulnerabilities. However, in the past, the BlackLotus bootkit has managed to do so through malware infections.
Especially in the case of GRUB2, the vulnerabilities could be exploited to bypass Secure Boot and install stealthy bootkits or potentially bypass other security mechanisms, such as BitLocker.
Installing such bootkits can give threat actors complete control over the device. They can control the boot process and operating system, compromise additional devices, and perform other malicious activities.
Microsoft says that AI Security Copilot dramatically accelerated the process of discovering vulnerabilities in bootloaders, saving about 1 week of time that would have been required for manual analysis. This success shows that AI can be a game-changer in cybersecurity, especially for detecting zero-day vulnerabilities.
See also: New RESURGE malware exploits Ivanti vulnerability

The tool was able to detect unknown bugs, but it also provided targeted mitigation recommendations, which could speed up the release of security updates.
Using the findings in the analysis, Microsoft says that Security Copilot identified similar bugs in projects that use shared code with GRUB2, such as U-boot and Barebox.
GRUB2, U-boot, and Barebox released security updates for the vulnerabilities in February 2025, so updating to the latest versions should fix the vulnerabilities.
Microsoft's vulnerability discovery is very important, as bootloaders are a key part of an operating system's booting system. If a hacker exploits a vulnerability at this stage, they can gain control of the system, making the attack very difficult to detect and counter.
See also: WordPress: The vulnerabilities most used by hackers in Q1 2025
It seems that artificial intelligence will be increasingly used to prevent attacks in the future. We have seen AI being used by attackers, but it can also be a powerful weapon for security!
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
