Tag: Microsoft Defender

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants
News

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

A cross-tenant blind spot that enables attackers to get around Microsoft Defender for Office 365 defenses by using Teams' guest access functionality has been revealed by cybersecurity experts. According to a report by Ontinue security expert Rhys Downing, when users work as guests in another tenancy, their rights are solely established by that hosting environment, not by their home company. These developments make it easier to collaborate, but they also increase the burden of making sure those external environments are reliable and secure. The development coincides with Microsoft launching a new Teams feature this month that enables users to communicate via email with anybody, including non-users of the enterprise communications platform read more about MS Teams Guest Access Can ...
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
News

Akira ransomware abuses CPU tuning tool to disable Microsoft Defender

In attacks from security tools and EDRs operating on target computers, the Akira ransomware disables Microsoft Defender by misusing a genuine Intel CPU tuning driver. Threat actors register the misused driver, 'rwdrv.sys' (used by ThrottleStop), as a service in order to obtain kernel-level access. 'hlpdrv.sys,' a malicious malware that manipulates Windows Defender to disable its defenses, is probably loaded by this driver. This is an example of a "Bring Your Own Vulnerable Driver" (BYOVD) attack, in which threat actors utilize authentic signed drivers with known flaws or vulnerabilities that could be exploited to escalate privileges. A malicious tool that disables Microsoft Defender is then loaded using this driver read more about Akira ransomware abuses CPU tuning tool to disabl...
Microsoft Defender for Office 365 now blocks email bombing attacks
News

Microsoft Defender for Office 365 now blocks email bombing attacks

According to Microsoft, email bombing threats will now be automatically detected and blocked by its Defender for Office 365 cloud-based email protection package. Defender for Office 365 (formerly known as Office 365 Advanced Threat Protection or Office 365 ATP) defends businesses dealing with sophisticated threat actors and high-risk industries against harmful threats from links, emails, and collaboration platforms. In a Microsoft 365 message center update, Redmond writes, We're introducing a new detection capability in Microsoft Defender for Office 365 to help protect your organization from a growing threat known as email bombing. This type of exploitation overwhelms systems or obscures essential messages by flooding mailboxes with large amounts of email. Security teams will be ...
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
News

New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender

'Defendnot' is a new utility that can disable Microsoft Defender on Windows devices by registering a phony antivirus program, even if there isn't any actually installed. The method makes advantage of an undocumented Windows Security Center (WSC) API, which antivirus software uses to inform Windows that it has been installed and is now in charge of the device's real-time security. To prevent conflicts from running several security apps on the same device, Windows immediately disables Microsoft Defender when an antivirus product is registered. This API is abused by the Defendnot utility, developed by researcher es3n1n, which registers a phony antivirus program that passes all of Windows' validation checks. The tool is built on a prior project called no-defender, which spoof regi...
Microsoft Defender will isolate undiscovered endpoints to block attacks
News

Microsoft Defender will isolate undiscovered endpoints to block attacks

Microsoft is testing a new Defender for Endpoint feature that will prevent communication from and to unknown endpoints in order to prevent lateral network movement attempts by attackers. Earlier this week, the business said that this is accomplished by limiting the IP addresses of devices that have not yet been identified or added to Defender for Endpoint. According to Redmond, the new capability would limit incoming and outgoing communication with devices utilizing confined IP addresses, preventing threat actors from spreading to additional non-compromised devices. Defender for Endpoint immediately disrupts attacks to contain IP addresses linked to devices that have not yet been found or that have not been onboarded read more about Microsoft Defender will isolate undiscovered en...
Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers
News

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers

Information thieves including ACR Stealer, Lumma, and Meduza are being distributed through a new campaign that takes use of a security hole in the Microsoft Defender SmartScreen that has since been patched. Fortinet FortiGuard Labs reported that it discovered the stealer campaign, which used booby-trapped files to exploit CVE-2024-21412 (CVSS score: 8.1) and was aimed at Spain, Thailand, and the United States. Through the use of the high-severity vulnerability, an attacker can evade SmartScreen defenses and deliver malicious payloads. In February 2024, Microsoft provided a monthly security update that resolved this problem. According to security researcher Cara Lin, attackers first trick victims into clicking on a specially created link that leads to a URL file intended to downlo...
Microsoft Defender Thwarts Large-Scale Akira Ransomware Attack
News

Microsoft Defender Thwarts Large-Scale Akira Ransomware Attack

The Akira ransomware perpetrators targeted an unidentified industrial firm in early June 2023, but Microsoft stated on Wednesday that a "large-scale remote encryption attempt" was thwarted in part because to a user containment feature in Microsoft Defender for Endpoint. The operator is being tracked by the internet giant's threat intelligence unit under the name Storm-1567. As a defensive evasion strategy, the assault made use of devices that were not onboarded to Microsoft Defender for Endpoint. Before encrypting the devices using a compromised user account, the attack carried out a number of reconnaissance and lateral movement operation read more Microsoft Defender Thwarts Large-Scale Akira Ransomware Attack. Stay informed with the best cybersecurity news and raise your cybers...
Microsoft Defender no longer flags Tor Browser as malware
News

Microsoft Defender no longer flags Tor Browser as malware

Because of the revised tor.exe file it included, recent versions of the TorBrowser were mistakenly labeled as potential threats by Windows Defender. Users were warned about a potential virus, which caused some commotion, although these were false positives. An update on this is available from TorBrowser. After speaking with Microsoft about the problem, TorBrowser got a clear response. "We've reviewed the submitted files and determined that they do not meet our definitions of malware or unwanted programs," Microsoft said. Users who continue to notice this false positive can update and remove any earlier flags by the simple guidelines provided by Microsoft read more Microsoft Defender no longer flags Tor Browser as malware. Stay informed with the best cybersecurity news and raise y...