Watch out - Microsoft Defender is flagging some legitimate URLs as harmful

A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
(Image credit: Shutterstock)

Microsoft’s own Defender antivirus program has erroneously labeled a number of safe links as malicious, sowing confusion among dozens of users. 

After one of the affected users posted about the problem on Reddit, others quickly chimed in, confirming they had seen the same issue. For some, Zoom links were classified as malicious, while for others, Google’s links, as well.

Soon after being tipped off, Microsoft took to Twitter to acknowledge the problem and to say that its engineers were working on a fix.

Trouble viewing alerts

"We're investigating an issue where legitimate URL links are being incorrectly marked as malicious by the Microsoft Defender service. Additionally, some of the alerts are not showing content as expected," Microsoft said

"We've confirmed that users are still able to access the legitimate URLs despite the false positive alerts. We're investigating why and what part of the service is incorrectly identifying legitimate URLs as malicious."

A later update on the Microsoft 365 Admin Center portal stated that admins can expect an “increased number” of high-severity email message alerts saying “A potentially malicious URL click was detected”, and that they can also expect trouble viewing the details by pressing the “View alerts” link in the messages. 

"We're reviewing service monitoring telemetry to isolate the root cause and develop a remediation plan," Microsoft said. "Impact is specific to any admin served through the affected infrastructure."

A few hours later, Microsoft issued yet another update, saying the false positive issue has been addressed. Apparently, the problem was in the SafeLinks feature, and its engineers fixed it by reverting recent updates.

“We determined that recent additions to the SafeLinks feature resulted in the false alerts and we subsequently reverted these additions to fix the issue,” Microsoft said in a tweet. “More detail can be found in the Microsoft 365 admin center under DZ534539.”

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
A hand laying out a password
Microsoft fixes concerning issue with its Entra ID authentication tool
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Close up of Leica M11-P viewfinder
I wince at the prospect of the rumored Leica M11-V – here's why
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time