Microsoft Defender shoots down legit URLs as malicious
- Reference: 1680114672
- News link: https://www.theregister.co.uk/2023/03/29/microsoft_defender_url_alerts/
- Source link:
Users are [1]complaining that sites like Zoom and Google are being tagged as potentially dangerous, triggering a flood of alerts. To add to the problem, one netizen wrote that the Defender portal is "up and down," making it difficult to investigate the alerts.
"We just got two email alerts regarding a malicious link being clicked but when we try to browse the security portal, it errors out," a Redditor [2]wrote .
[3]
A system admin said that after getting two email alerts about a malicious link being clicked, they were unable to browse the security portal.
[4]
[5]
And one Register reader told us: "Our organization has received hundreds of malicious URL alerts from Office 365 for zoom.us links. These false positives take us a long time to investigate. Microsoft finally admitted that this is affecting hundreds of accounts and tenants worldwide."
Indeed, the Windows giant is aware of the problem, [6]tweeting out a note at 1304 UTC that it's looking into the issue.
[7]
"We're investigating an issue where legitimate URL links are being incorrectly marked as malicious by the Microsoft Defender service," Redmond wrote. "Additionally, some of the alerts are not showing content as expected."
The biz is tracking the problem as [8]DZ534539 .
A user noted that Microsoft in an admin center message said that admins "may be receiving an unexpected amount of high severity alert email message."
[9]
"The high severity alert emails refer to 'A potentially malicious URL click was detected,'" according to the note. "Additionally, admins may be unable to view alert details using the 'View alerts' link in the emails.'"
Microsoft said it is trying to isolate the root cause by poring over service monitoring.
An hour after the first tweet, Redmond followed up, saying that "users are still able to access the legitimate URLs despite the false positive alerts. We're investigating why and what part of the service is incorrectly identifying legitimate URLs as malicious."
Regardless of whether they can still access the sites, techies are saying the whole thing is a pain.
[10]Germany sours on Microsoft again, launches antitrust review
[11]Oh, really? Microsoft worries multicloud complicates security and identity
[12]Google reminds everyone it too can offer an AI code-suggestion bot
[13]Microsoft enlarges its cockpit of Copilots to include security
Defender is "classifying all ZOOM.US a malicious URL, detecting all clicks as potentially Malicious," an admin wrote. "We've checked several of those URLs and all them seem a legit resource."
Perusing the Reddit comments, Zoom links seem to be a particular problem, but not the only one. A poster on Reddit wrote that "pictures sent from employees personal GMAIL to work accounts getting flagged (they send pics of their receipts) and zoom links. Many delayed from yesterday."
All this comes two months after users reported that Defender for Endpoint's attack surface reduction (ASR) rules suddenly were [14]removing icons and application shortcuts from the Taskbar and Start Menu in both Windows 10 and 11.
Cynics might even say Defender has had [15]a bit of a [16]false positive problem in the past. ®
Updated to add
Microsoft this afternoon figured out that changes to SafeLinks, which scans incoming email for malicious hyperlinks and attachments, caused the problem.
"We determined that recent additions to the SafeLinks feature resulted in the false alerts and we subsequently reverted these additions to fix the issue," the company [17]tweeted .
Get our [18]Tech Resources
[1] https://www.reddit.com/r/sysadmin/comments/125k2af/microsoft_defender_issues/
[2] https://www.reddit.com/r/sysadmin/comments/125ja9c/got_an_email_about_malicious_link_clicked_but_365/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCS1AJOFTbN@kEvrudu5XQAAAIo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCS1AJOFTbN@kEvrudu5XQAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCS1AJOFTbN@kEvrudu5XQAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://twitter.com/MSFT365Status
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCS1AJOFTbN@kEvrudu5XQAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://twitter.com/MSFT365Status/status/1641072504880914433
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCS1AJOFTbN@kEvrudu5XQAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/03/29/microsoft_german_antitrust/
[11] https://www.theregister.com/2023/03/29/microsoft_mulitcloud_identities_risk/
[12] https://www.theregister.com/2023/03/28/google_replit_ai_coding/
[13] https://www.theregister.com/2023/03/28/microsoft_security_copilot/
[14] https://www.theregister.com/2023/01/13/happy_friday_13th_microsoft_defender/
[15] https://www.theregister.com/2017/04/03/ms_defender_bluber_false_alarm/
[16] https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/
[17] https://twitter.com/MSFT365Status/status/1641147963270365203
[18] https://whitepapers.theregister.com/
Re: Hmmmm??
No need to get paranoid, it's not like Microsoft would do anything nefarious like deliberately sending bad CSS to a competitors web browser
Re: Hmmmm??
And yet again, "updates" released to the rest of the world to beta test before the US wakes up.
Working as designed.
I mean, from MS perspective Zoom and Google are very detrimental to their bottom line, so obviously should be blocked.
I don't see DZ534539. I do see DZ534548 for alert URLs that will not work, something that has been happening for the last few days. The URLs normally sort themselves out half a day later, which isn't really what one expects from a security product.
Because DZ534539 has already been moved over to the Issue History tab.
That's just low. Especially when the problem isn't fixed because links dating from the incident live period still aren't opening.
It looks as if DZ534548 is solely there to justify moving DZ534539 off of the Active tab.
Well to be fair to MS, Zoom installing a web browser without asking is a security risk
Canary Release
"We determined that recent additions to the SafeLinks feature resulted in the false alerts and we subsequently reverted these additions to fix the issue"
aka Testing in Production. Microsoft loves it. Here's the thing though. The canary is not supposed to be the *only* safety feature in the mine. If you have a pile of dead canaries, the mine is *not* safe.
They all do it
Defender seems to be no different from the other options. Periodically we have to re-white list our website in order to avoid triggering warnings.
I've forgotten which one as it hasn't happened for a few months but trust me if it were possible to have an undiluted rant at Microsoft I wouldn't miss the opportunity.
Hmmmm??
Does Microsoft make a competing product? Maybe we could have a Teams meeting to discuss?