AI Vulnerability Finding
Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code:
Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison.
Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit.
The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device.
Nothing major here. These aren’t exploitable out of the box. But that an AI system can do this at all is impressive, and I expect their capabilities to continue to improve.
Subscribe to comments on this entry
Davide • April 11, 2025 7:58 AM
hmm… microsoft sell AI service… microsoft has quoted Stock exchange… and microsoft say something that can help her selling more licenses and rise his quote… hmm…
But this is not as the microsoft quantum computer chip that probably do not exists and cannot exists?
https://tech.slashdot.org/story/25/02/19/1651235/microsoft-reveals-its-first-quantum-computing-chip-the-majorana-1
https://slashdot.org/story/25/03/07/1350230/microsoft-quantum-computing-breakthrough-faces-fresh-challenge
https://slashdot.org/story/25/03/19/088253/microsoft-quantum-computing-claim-still-lacks-evidence
Or this AI App that is managed 100% by humans in the Philippines and 0% by AI?
https://techcrunch.com/2025/04/10/fintech-founder-charged-with-fraud-after-ai-shopping-app-found-to-be-powered-by-humans-in-the-philippines/
There are other cases where something AI-based was totally of partially managed by real human.