#barebox
Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders.
Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders
Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders.
www.bleepingcomputer.com
March 31, 2025 at 7:57 PM
Microsoft says it used its AI-powered Security Copilot to discover previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders (Bill Toulas/BleepingComputer)

Main Link | Techmeme Permalink
April 1, 2025 at 11:41 PM
🎙️ Next talk at Embedded Recipes 2026!

Michael Tretter is on stage with a highly practical session: "Open Source Tools for Secure Boot on Rockchip RK3588".

#EmbeddedRecipes2026 #EmbeddedLinux #SecureBoot #Rockchip #RK3588 #OPTEE #barebox #OpenSource #Pengutronix
May 27, 2026 at 12:53 PM
this is OpenBSD 7.9 installed to an USB stick on RK3588-powered MNT Pocket Reform. the display was set up by the @barebox bootloader for which i commissioned @ailurux to port the RK3588 DSI etc display drivers. the framebuffer is passed to OpenBSD via EFI GOP […]

[Original post on mastodon.social]
May 26, 2026 at 8:37 PM
Microsoft Uses AI To Find Flaws In GRUB2, U-Boot, Barebox Bootloaders

Microsoft's Security Copilot, an AI tool, found 20 new vulnerabilities in open-source bootloaders like GRUB2, U-Boot, and Barebox. Eleven flaws were found in GRUB2, the bootloader for many Linux di…

#copilot #geminiai #microsoft
Microsoft Uses AI To Find Flaws In GRUB2, U-Boot, Barebox Bootloaders
Microsoft's Security Copilot, an AI tool, found 20 new vulnerabilities in open-source bootloaders like GRUB2, U-Boot, and Barebox. Eleven flaws were found in GRUB2, the bootloader for many Linux distributions, including buffer overflows and cryptographic weaknesses. U-Boot and Barebox, used in embedded devices, had nine buffer overflows, primarily in filesystem parsing. These vulnerabilities could potentially allow attackers to bypass security measures and execute arbitrary code. Exploiting these flaws likely requires local access, but historical attacks show how malware can achieve this. Microsoft worked with maintainers to address the issues and contributed fixes, with updates released in February 2025. The AI tool significantly sped up the vulnerability discovery process, saving the team a week of manual work. Microsoft highlights the crucial role of information sharing in the cybersecurity community as AI advances. This approach helps counter malicious actors' use of AI for escalating attacks. Google also recently announced Sec-Gemini v1, an AI model for advancing cybersecurity. Microsoft emphasizes the importance of AI in rapid vulnerability detection, remediation, and security operations to counter malicious activities.
news.slashdot.org
April 6, 2025 at 8:30 PM
heh, barebox has a web based demo https://www.barebox.org/demo/?graphic=0
JSBarebox
www.barebox.org
October 25, 2025 at 8:40 PM
@ailurux @a3f @barebox we also have a fixup script for booting the current OpenBSD aarch64 image including instructions to get started: https://source.mnt.re/reform/mnt-reform-barebox/-/blob/main/README-mnt.md#booting-openbsd
June 18, 2026 at 5:55 PM
Multiple Vulnerabilities in Barebox Bootloader Expose Embedded Systems to Code Execution Risks
Multiple Vulnerabilities in Barebox Bootloader Expose Embedded Systems to Code Execution Risks
Learn about CVE-2024-57260, CVE-2024-57261, & CVE-2024-57262 and their impact on Barebox bootloader vulnerabilities affecting embedded systems' security
securityonline.info
February 20, 2025 at 5:03 AM
i'm very happy to present the first release of the Barebox bootloader tailored for MNT Pocket Reform with RK3588 processor, bringing you an advanced bootloader with graphics and comfy shell […]

[Original post on mastodon.social]
June 18, 2026 at 5:50 PM
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot
cybersecuritynews.com
April 1, 2025 at 9:06 AM
Microsoft utilise l'IA pour détecter des vulnérabilités dans les chargeurs d'amorçage GRUB2, U-Boot et Barebox

👉 www.bleepingcomputer...
April 10, 2025 at 9:50 AM
March 31, 2025 at 8:16 PM
it's a brand new month and @holo_memory wrote an MNT June Update that is packed with cool developments, check it out: https://mntre.com/media/reform_md/2026-06-30-june-update.html

One little spoiler: we're at 20x Quasar 6490 preoders, 5 more and we can start prepping the first batch!
MNT June 2026 Update
We faced a heatwave, but we still kept going: Barebox bootloader release, MNT Quasar 6490 launch, Pocket Reform mainboard 2.0 in production are just three examples of our accomplishments this month.
mntre.com
July 1, 2026 at 1:19 PM
🟠 CVE-2026-34963 - High (8.4)

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE ...

https://www.thehackerwire.com/vulnerability/CVE-2026-34963/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
May 12, 2026 at 3:59 AM
@ailurux @a3f @barebox BTW the MNT logo with rainbow in the corner is a nod to the very first MNT Reform 1.0 from January 2019, with i.MX6QP processor (damn, that's over 7 years ago)
June 18, 2026 at 6:53 PM
AI Vulnerability Finding

Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code:

Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-chan…

#hackernews #microsoft #news
AI Vulnerability Finding
Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code: Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit. The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device...
www.schneier.com
April 12, 2025 at 1:40 PM
Sunday geekery things done:
• system upgrade (apt and others) ✅
• replaced U-Boot bootloader on #mntpocketreform with Barebox ✅
• bit of wiki gardening in personal #vimwiki knowledge base
August 23, 2026 at 2:35 PM
Notícia da SecurityOnline

"Múltiplas Vulnerabilidades no Bootloader Barebox Expostos Sistemas Embarcados a Riscos de Execução de Código" #bolhasec
Multiple Vulnerabilities in Barebox Bootloader Expose Embedded Systems to Code Execution Risks
Learn about CVE-2024-57260, CVE-2024-57261, & CVE-2024-57262 and their impact on Barebox bootloader vulnerabilities affecting embedded systems' security
securityonline.info
March 11, 2025 at 10:30 PM