home.social

#microsoftdefender — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #microsoftdefender, aggregated by home.social.

fetched live
  1. How is #MicrosoftDefender security.microsoft.com/quarant still so utterly awful? This is their standard spam filter for Outlook, likely forced on over half the UK's academics alone.

    Some flaws we can perhaps lay at the local administration's configuration (some setups are far better than others in terms of the basic classification problem).

    But why oh why can't I tell it certain senders should always be accepted?

    Or, if I manually release an email from an account, might it offer to review anything else in quarantine from the same sender? It certainly doesn't seem to shift the weighting for classifying future emails from that person 🤷‍♂️

    I have regular collaborators with *.ac.uk or *.gov.uk email addresses ALSO using Microsoft Outlook which going back years seem always go to spam 😱

    #Spam #Outlook

  2. Use Defender for Office 365 Safe Links & Safe Attachments. These features protect users from malicious URLs and attachments in real time. Use with email, Teams, SharePoint & more. .

  3. Apply vulnerability management via Defender for Endpoint. Regularly patch and remediate vulnerabilities to reduce exploit risk. Ensure compliance and security best practices .

  4. Zero-Day Tool Blocks Microsoft Defender Updates

    Meet BigDiskBuster, a newly released zero-day tool that cleverly blocks Microsoft Defender updates by maxing out disk space, leaving users vulnerable until a fix is found. Its creator, Abdelhamid Naceri, a former Microsoft security researcher, has made the proof-of-concept tool publicly available on GitHub.

    osintsights.com/zero-day-tool-

    #ZeroDay #MicrosoftDefender #SupplyChain #EmergingThreats #VulnerabilityManagement

  5. NightmareEclipse Exploits Microsoft Defender Update Process

    Meet BigDiskBuster, a clever tool created by NightmareEclipse that cleverly blocks Microsoft Defender updates, leaving you stuck with your current version if it's running in the background. This proof-of-concept has been designed to prevent platform and security intelligence updates from installing.

    osintsights.com/nightmareeclip

    #MicrosoftDefender #Nightmareeclipse #Bigdiskbuster #Undefend #Windows

  6. Chaotic Eclipse released BigDiskBuster, a PoC that reportedly blocks Microsoft Defender platform and signature updates without disabling antivirus. This matters because endpoints may appear protected while relying on stale security content. #ThreatIntelligence #EndpointSecurity #MicrosoftDefender

    cyberworldops.eu/en/bigdiskbus

  7. Microsoft Defender Zero-Day Blocks Antivirus Updates

    A security researcher just released a clever tool called BigDiskBuster that can block Microsoft Defender updates, leaving your antivirus stuck in limbo. This sneaky proof-of-concept allows anyone to prevent Defender from getting the latest signature and platform updates, as long as the tool is running in the background.

    osintsights.com/microsoft-defe

    #ZeroDay #MicrosoftDefender #EmergingThreats #Proofofconcept #Vulnerability

  8. Configure Attack Surface Reduction (ASR) rules using InTune. There are dozens of default rules to add out of the box. ASR rules block common exploit techniques and reduce exposure to malware. Ensure compliance and security best practices .

  9. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    Pulse ID: 6aa8d2a1613e9e4ef7ab9819
    Pulse Link: otx.alienvault.com/pulse/6aa8d
    Pulse Author: Tr1sa111
    Created: 2026-09-15 05:07:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #MicrosoftDefender #Windows #OTX #Tr1sa111

  10. 📢 ShieldCrash : nouveau zero-day ciblant Microsoft Defender, bypass de patch successif

    Cet article rapporte la divulgation publique d'un nouvel exploit zero-day baptisé ShieldCrash, ciblant Microsoft Defender sur des systèmes Windows entièrement patchés, y compris ceux ayant appliqué les correctifs de septembre 2026.

    📖 cyberveille : cyberveille.ch/posts/2026-09-1
    🌐 source : securityweek.com/new-shieldcra
    🟢 vérification factuelle haute
    #MicrosoftDefender #ShieldCrash #Cyberveille

  11. From Fake DocuSign to ScreenConnect: Attack Blocked

    Threat actors exploited trusted brands and cloud services in a sophisticated web campaign combining fraudulent DocuSign workflows, Florida healthcare screening lures, and deceptive cloud infrastructure to deploy ConnectWise ScreenConnect Access clients. The attack utilized Cloudflare Pages hosting with fake Cloudflare verification workflows to establish legitimacy. Victims were socially engineered to download a ZIP archive containing a malicious HTA file that employed Base64-encoded VBScript, fake Adobe interfaces, UAC privilege escalation, and Microsoft Defender SmartScreen registry modifications. The attack leveraged living-off-the-land techniques using native Windows tools like mshta.exe, curl.exe, and msiexec.exe for silent ScreenConnect installation, ultimately providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and blocked at the web entry point before payload delivery could occur.

    Pulse ID: 6aa374470d15d76b861b2f68
    Pulse Link: otx.alienvault.com/pulse/6aa37
    Pulse Author: AlienVault
    Created: 2026-09-11 03:23:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Cloud #ConnectWise #CyberSecurity #Healthcare #InfoSec #Mac #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #Rust #ScreenConnect #VBS #Windows #ZIP #bot #AlienVault

  12. Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender

    cyberworldops.eu/en/shieldcras

  13. CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh #OffSeq #ZeroDay #MicrosoftDefender #Infosec

  14. MsMpEng.exe bringt meinen Laptop ordentlich zum Pusten. Einfluss darauf habe ich nicht.

    Ich würde so gerne bei der Arbeit ohne Überwachungs-OS arbeiten*.

    Danke, M$.

    *passende Job-Angebote für Softwareentwicklung/-architektur bitte per DM

    #Microsoft #MicrosoftDefender #DigitaleSouveränität

  15. Microsoft Defender Exposed to New Zero-Day Exploit

    A security researcher known as Nightmare Eclipse has just dropped a proof-of-concept exploit for a new Microsoft Defender zero-day vulnerability, dubbed ShieldCrash, which surprisingly still works on Windows systems that have already applied the latest September patches. This marks the researcher's 11th Microsoft zero-day exploit to be made…

    osintsights.com/microsoft-defe

    #ZeroDay #MicrosoftDefender #Shieldcrash #NightmareEclipse #Proofofconcept

  16. Microsoft is tracking an active campaign targeting Windows users through fake download pages that imitate well-known companies. The downloaded files can remain on the system, evade Microsoft Defender checks, make removal harder and disable services used for Windows security updates.

    Affected sectors include healthcare, manufacturing, gaming, technology, transport, government and education, with most reported cases tied…

    en.hacks.gr/kindynos-gia-chris

    #Windows #MicrosoftDefender #SilverFox #ValleyRAT

  17. Chaotic Eclipse released ShieldCrash PoC, described as a patch bypass for CVE-2026-69414 ShieldBreak in Microsoft Malware Protection Engine. If valid, Defender privilege escalation remains exploitable despite the official fix, requiring re-validation of mitigations. #ShieldBreak #MicrosoftDefender #PatchBypass

    cyberworldops.eu/en/microsoft-

  18. Microsoft Defender Exposes New Zero-Day Vulnerability

    A security researcher has uncovered a new zero-day vulnerability, dubbed ShieldCrash, which exposes a gaping hole in Microsoft Defender's patch for CVE-2026-69414, leaving all supported Windows versions open to attack. This shocking exploit allows hackers to read arbitrary files with SYSTEM privileges, putting even the most secure systems at…

    osintsights.com/microsoft-defe

    #ZeroDay #Shieldbreak #Cve202669414 #MicrosoftDefender #EmergingThreats

  19. Microsoft Defender Zero-Day Exploited to Grant SYSTEM Access

    A new zero-day exploit called "ShieldCrash" has been published by an anonymous researcher, granting SYSTEM-level access to affected Microsoft Defender systems. This alarming vulnerability comes hot on the heels of Microsoft's September 2026 Patch Tuesday security updates.

    osintsights.com/microsoft-defe

    #MicrosoftDefender #ZeroDay #Exploit #Shieldcrash #SystemAccess

  20. A researcher using the name Chaotic Eclipse claims that a new test, ShieldCrash, gets around Microsoft’s recent fix for the ShieldBreak issue in Defender.

    The test was run on the latest Windows version and, according to the researcher, can read any file with the operating system’s highest permissions.

    Microsoft has not confirmed that the fix can be bypassed.

    The update is included from Microsoft Defender version…

    en.hacks.gr/nea-dokimi-feretai

    #MicrosoftDefender #ShieldCrash #ShieldBreak #Windows

  21. Malware Modules Disable Windows Update, Defender for Crypto Mining

    Meet LockAppHost, a notorious malware module that cripples your Windows defenses by disabling updates and Microsoft Defender, making way for a sneaky cryptocurrency miner to take over. By weakening your machine's security, it allows the miner to run undetected, wreaking havoc on your system.

    osintsights.com/malware-module

    #CryptoMiningMalware #MalwareOperations #WindowsUpdate #MicrosoftDefender #SupplyChain

  22. Microsoft Defender mistakenly targets Google search links

    Microsoft Defender for Office 365's Safe Links feature has mistakenly flagged Google search links as malicious, blocking users from accessing legitimate search results. This faulty security classification is currently preventing users from opening harmless links.

    osintsights.com/microsoft-defe

    #MicrosoftDefender #Office365 #SafeLinks #UrlBlocking #FalsePositives

  23. Turn on tamper protection in Defender settings. Prevent attackers from disabling security features by enforcing tamper protection. Ensure compliance and security best practices

  24. Microsoft Disregards Defender Alerts as False Positives

    If you've recently updated Microsoft Defender Antivirus, you might be seeing annoying false alarms claiming it's turned off - but don't worry, it's still working hard to protect you. These pesky alerts are affecting all supported Windows versions, including Windows 11 26H1 and Windows Server 2025.

    osintsights.com/microsoft-disr

    #MicrosoftDefender #FalsePositives #Windows11 #WindowsServer2025 #Antivirus

  25. ‘Antivirus Is Turned Off’—Microsoft Confirms Windows Update Mistake

    Microsoft has now confirmed that new warnings alarming Windows users that “Microsoft Defender Antivirus is turned off” are…
    #NewsBeep #News #Technology #CA #Canada #Microsoft #MicrosoftDefender #WindowsLatest
    newsbeep.com/ca/877041/

  26. 📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

    A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

    🔗 cyber.netsecops.io/articles/sh

  27. Microsoft Defender Driver Exploited to Disable Security Software

    Researchers at Check Point have uncovered a technique that exploits Microsoft Defender's own driver to disable security software, leaving Windows 7 to 11 users vulnerable to attack. This clever hack requires no external driver or software vulnerability, making it a worrying threat.

    osintsights.com/microsoft-defe

    #MicrosoftDefender #Btrsys #WindowsExploitation #KernellevelThreats #DefensiveEvasion

  28. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  29. 📢 Zero-day ShieldBreak dans Microsoft Defender : escalade de privilèges SYSTEM, PoC public disponible

    BleepingComputer, publié le 17 août 2026. L'article rapporte la divulgation publique d'une vulnérabilité zero-day dans Microsoft Defender, nommée ShieldBreak, par le chercheur en sécurité Nightmare Eclipse, sans notification préalable à…

    📖 cyberveille : cyberveille.ch/posts/2026-08-2
    🌐 source : bleepingcomputer.com/news/secu
    🟡 vérification factuelle moyenne
    #MicrosoftDefender #PoCPublic #Cyberveille

  30. Device Roles in Microsoft Defender XDR: Better Context for Threat Hunting and Detection Engineering
    #MicrosoftDefender
    academy.bluraven.io/blog/devic

  31. 📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

    A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

    🔗 cyber.netsecops.io/articles/sh

  32. 📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

    A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

    🔗 cyber.netsecops.io/articles/sh

  33. Nightmare Eclipse published a zero-day proof-of-concept called ShieldBreak targeting Microsoft Defender. The exploit abuses a user-mode callback generated during cloud-hydrated file scanning via the Cloud Filter API, allowing a non-privileged user to escalate to SYSTEM.

    #ShieldBreak #WindowsZeroDay #MicrosoftDefender #PrivilegeEscalation

    cyberworldops.eu/en/shieldbrea

  34. A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

    #ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender

    cyberworldops.eu/en/shieldbrea

  35. Enable email authentication (SPF, DKIM, DMARC). These protocols prevent email spoofing and protect against phishing attacks. Ensure compliance and security best practices .

  36. Powrót do przeszłości w cyberbezpieczeństwie. Nowy robak kradnie kryptowaluty przez port USB

    W erze wyrafinowanych ataków chmurowych i wszechobecnego phishingu cyberprzestępcy przypomnieli sobie o starym, sprawdzonym wektorze ataku.

    Microsoft wykrył nowego, samorozprzestrzeniającego się robaka, który infekuje komputery przez zwykłe pendrive’y. Jego jedynym celem jest bezszelestne wyczyszczenie twojego portfela kryptowalut.

    Odkryte przez Microsoft zagrożenie otrzymało nazwę Crypto Clipper. To wyjątkowo sprytny kawałek kodu, który łączy archaiczne metody infekcji z najnowocześniejszymi technikami zacierania śladów. Jak ostrzegają badacze, mamy tu do czynienia z „lekkim backdoorem”, który potrafi wyrządzić gigantyczne szkody.

    Amerykańskie prawo ważniejsze niż europejska prywatność? Microsoft w centrum afery z holenderskimi urzędnikami

    Cichy pasożyt na dysku

    Złośliwe oprogramowanie ukrywa się na dyskach USB pod postacią złośliwych skrótów systemu Windows (.lnk), które uruchamiają szkodliwy kod. Co ciekawe, aby uśpić czujność ofiary, robak skanuje zawartość pendrive’a i nadaje swoim skrótom nazwy łudząco podobne do plików, które już się na nim znajdują. Gdy nieświadomy użytkownik uruchomi taki spreparowany skrót, Crypto Clipper instaluje się w systemie i natychmiast przechodzi w tryb nasłuchu.

    W przeciwieństwie do głośnego ransomware, ten robak działa bezszelestnie. Jego głównym zadaniem jest monitorowanie systemowego schowka w poszukiwaniu ciągów znaków przypominających adresy portfeli kryptowalutowych oraz tzw. seed phrases (ciągów 12 lub 24 słów odzyskujących dostęp do zgromadzonych środków). Gdy skopiujesz adres, by wykonać przelew, złośliwy kod w ułamku sekundy podmienia go na adres kontrolowany przez hakera. Jeśli nie zweryfikujesz go przed zatwierdzeniem transakcji, twoje środki bezpowrotnie znikną.

    Microsoft nie ujawnił pełnej skali tej kampanii, ale użytkownicy systemu Windows powinni zachować szczególną ostrożność przy podłączaniu nieznanych nośników USB.

    Na podmianie adresów inwigilacja się jednak nie kończy. Po wykryciu interesujących danych robak wykonuje pięć zrzutów ekranu w odstępie 10 sekund. To pozwala przestępcom zdobyć cenny kontekst operacyjny: widzą, z jakich aplikacji korzystasz, ile masz środków i jak wygląda twoje prywatne środowisko pracy.

    Zakamuflowany dzięki sieci Tor

    To, co czyni Crypto Clippera tak niebezpiecznym, to sposób, w jaki komunikuje się ze swoimi twórcami. Tradycyjne złośliwe oprogramowanie zazwyczaj łączy się z serwerami dowodzenia (C2) za pomocą otwartych protokołów, co ułatwia jego wykrycie i zablokowanie przez programy antywirusowe.

    Tutaj hakerzy zastosowali zupełnie inną taktykę. Robak pobiera przenośnego klienta sieci Tor i kieruje cały skradziony ruch przez lokalne proxy SOCKS5. Dzięki temu przesyłane dane są w pełni zanonimizowane, a wykrycie, dokąd trafiają kradzione kryptowaluty i zrzuty ekranu, staje się dla zapór sieciowych znacznie utrudnione.

    Historia zatacza koło

    Ten przypadek doskonale udowadnia, że w świecie cyberbezpieczeństwa najsłabszym ogniwem zawsze pozostaje człowiek, a zapomniane metody wciąż są zabójczo skuteczne. Warto przypomnieć, że to właśnie między innymi za pomocą zainfekowanych pamięci USB słynny robak Stuxnet zdołał przeniknąć do fizycznie odciętych od internetu irańskich zakładów i zniszczyć wirówki do wzbogacania uranu.

    Skala obu tych zjawisk jest oczywiście inna, ale mechanizm błędu pozostaje identyczny. Kiedyś przez USB niszczono tajne programy nuklearne, dziś czyści się portfele z Bitcoinów i innych kryptowalut. Warto o tym pamiętać, zanim następnym razem w ułamku sekundy zdecydujemy się podłączyć do komputera znaleziony w biurze nośnik danych.

    #bezpieczeństwoIT #CryptoClipper #cyberbezpieczeństwo #hacking #kradzieżKryptowalut #MicrosoftDefender #siećTor #Stuxnet #wirusZUSB
  37. New zero-day Local Privilege Escalation (EoP) flaw in Microsoft Defender: CVE-2026-50656 (RoguePlanet)! 🚨

    Low-privilege users can abuse a TOCTOU race condition to hijack system paths and spawn an NT AUTHORITY\SYSTEM shell. Deep dive analysis here:👇

    denizhalil.com/2026/06/18/cve-

    #CVE202650656 #MicrosoftDefender #infosec

  38. Akira, LimeWire, and the Sour Taste of Data Exfiltration

    In a recent ransomware attack, threat actors accessed a victim's hypervisor and created a new virtual machine to stage and launch Akira ransomware. The forensic investigation revealed the attackers disabled Microsoft Defender immediately, installed WinRAR for data staging, and used Easyupload.io, a file transfer website owned by LimeWire, for data exfiltration. The threat actor also utilized WinSCP and enumerated Active Directory users and computers. The newly instantiated VM lacked security tooling, allowing the attacker to operate uninhibited. Analysis of the VHDX file provided clear evidence of the attack progression, showing the threat actor moved quickly through their operations without employing sophisticated anti-forensics techniques. The incident highlights the need for organizations to monitor environments for unusual access and new endpoint creation.

    Pulse ID: 6a2c3a9558633c03af0b3177
    Pulse Link: otx.alienvault.com/pulse/6a2c3
    Pulse Author: AlienVault
    Created: 2026-06-12 16:57:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #CyberSecurity #Endpoint #ICS #InfoSec #Mac #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RansomWare #WinRAR #WinSCP #bot #AlienVault

  39. A new Microsoft Defender zero-day, 'RoguePlanet,' has been publicly disclosed, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and 11 systems. Security researcher Chaotic Eclipse released the PoC after a Patch Tuesday, reigniting the debate over vulnerability disclosure practices. The exploit, a race condition, proves viable despite variable reliability, posing…

    tpp.blog/2qzsebf

    #cybersecurity #microsoftdefender #rogueplanet

    🤖 This post was AI-generated.

  40. Microsoft Defender Zero-Day Exploited for SYSTEM Privileges

    A newly discovered Microsoft Defender zero-day exploit, dubbed RoguePlanet, can spawn a Windows command prompt with SYSTEM privileges, posing a significant threat to fully patched Windows 10 and 11 devices. This cleverly crafted exploit uses a hit-or-miss race condition to gain elevated access, with some machines surprisingly vulnerable to…

    osintsights.com/microsoft-defe

    #MicrosoftDefender #ZeroDay #Rogueplanet #SystemPrivileges #Windows10

  41. I can't believe that there doesn't seem to be a way to show you which #malware (name and details) #MicrosoftDefender believes to have found on #Mac under #macOS. Can only find out the file path, but nothing else?!

    What's wrong with #ProductOwner|s these days?! 😠

    #Microsoft #Defender

Share on Mastodon

Enter the server where you have an account.