Tech News
← Home  ·  All topics

Microsoft Defender

9 GoKawiil briefs on this topic

Microsoft Defender Offers Built-In Malware Scanning for Windows 11 PCs

Windows 11 includes Microsoft Defender, a free antivirus tool within Windows Security that automatically scans for threats and logs its findings under Virus & threat protection. Users can review allowed threats and protection history, run a deeper Full scan, or use an offline scan via Windows Recovery Environment to catch malware that hides from standard scans. The Firewall & network protection settings should also be checked to ensure all three connection types are protected.

Microsoft patches false 'Defender Antivirus is off' alert bug

Microsoft has fixed a glitch that made the Windows Security app falsely warn users that Defender Antivirus was disabled, even though it was running normally. The fix arrived in Defender Antivirus update version 4.18.26080.4, released September 17, after the problem had persisted since at least June in Windows Insider builds.

Iranian state hackers deploy CHOSEN BRICK malware against journalists and activists

Cybersecurity agencies from the U.S., U.K. and Netherlands, alongside the FBI, issued a joint advisory exposing an Iranian state-linked campaign using Windows malware called CHOSEN BRICK to spy on dissidents, journalists and activists. Attackers pose as trusted contacts or tech support over WhatsApp and Telegram, luring victims into launching disguised fake apps that secretly install the spyware and evade Windows Defender.

Researcher Discloses 'ShieldCrash' Zero-Day Exploit for Microsoft Defender

A researcher using the alias Nightmare Eclipse publicly released details of a new zero-day exploit dubbed 'ShieldCrash' targeting Microsoft Defender, timed to appear right after Microsoft's September 2026 Patch Tuesday updates. The exploit reportedly allows attackers to gain SYSTEM-level access on affected Windows machines, the highest level of privilege on the system.

Microsoft flags phishing campaign hiding invisible Unicode characters in finance-themed emails

Microsoft researchers identified a large phishing operation that inserts invisible Unicode 'Tags' characters inside finance-related keywords—splitting words like 'funding' into fragments—to slip past email filters that scan for suspicious terms. The campaign peaked at 2.37 million daily messages in late February and, despite a drop in volume by May, remains active, with Defender for Office 365 tracing it to 148 finance-themed sender domains.

Microsoft finds spammers hijacking AI-targeted ASCII smuggling to dodge email filters

Microsoft says spammers have repurposed ASCII smuggling, a technique once used mainly to sneak hidden prompt-injection instructions into AI systems, to disguise spam keywords and slip past Office 365 filters. The company detected daily signature hits jump from about 21,000 to over 1.3 million in early February, reaching 2.5 million within days before tapering off by mid-May.

Microsoft Defender for Office 365 mistakenly blocked Google Search links for hours

On September 2, Microsoft's Safe Links feature within Defender for Office 365 began misidentifying Google Search URLs shared in emails and Teams messages as malicious, blocking users from opening them. The outage, tracked internally as MO1465962, lasted about seven and a half hours before Microsoft resolved the faulty detection logic, though some users may have experienced lingering effects.

Microsoft Defender for Office 365 mistakenly blocks Google search links

Microsoft confirmed its Defender for Office 365 Safe Links feature is incorrectly flagging legitimate Google search URLs as malicious, showing users 'not safe' warnings when they try to click them. The company said the problem stems from an inaccurate security classification and is generating false alerts for IT admins in Microsoft Sentinel and the Defender portal. Pasting the blocked links directly into a browser does not bypass the warning.

Microsoft tells users to disregard false Defender Antivirus 'turned off' alerts

Microsoft confirmed a bug causing the Windows Security app to falsely display 'Microsoft Defender Antivirus is turned off' notifications after recent Defender updates, even though protection remains active. The issue, which has quietly affected Windows Insiders since June, now impacts all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025. Microsoft says a fix is in development and will roll out in a future Defender update.