Goto

Collaborating Authors

 microsoft defender


Microsoft Defender is falsely flagging Google links as malicious

PCWorld

PCWorld reports that Microsoft Defender for Office 365 is incorrectly flagging legitimate Google search URLs as malicious, causing false security alerts for users. The issue stems from the Safe Links feature, which is mistakenly blocking valid Google URLs instead of protecting against genuine threats. Microsoft has identified the cause and is working on a fix, though no timeline for an official patch has been confirmed yet. Even though Microsoft Defender is more than enough security on its own, its reputation has taken a bit of a hit this year. Over the last few months, vulnerabilities like RedSun and RoguePlanet were discovered (and later patched), while just last month Defender was showing false warnings that it was disabled even when it wasn't .


Windows 10 and 11 users are seeing a Defender warning that isn't real

PCWorld

PCWorld reports that Windows 10 and 11 users are seeing false warning messages claiming Microsoft Defender has been turned off, despite the security software remaining fully active. The issue stems from a recent antivirus update bug, causing incorrect notifications across multiple Windows versions. Microsoft is aware of the problem and is working on a fix expected in an upcoming update, so users should not panic. Over the past few days, some Windows 11 users have been getting incorrect warning messages about Microsoft Defender--the operating system's built-in security solution--being disabled.


Mapping Smarter, Not Harder: A Test-Time Reinforcement Learning Agent That Improves Without Labels or Model Updates

arXiv.org Artificial Intelligence

The Enterprise Intelligence Platform must integrate logs from numerous third-party vendors in order to perform various downstream tasks. However, vendor documentation is often unavailable at test time. It is either misplaced, mismatched, poorly formatted, or incomplete, which makes schema mapping challenging. We introduce a reinforcement learning agent that can self-improve without labeled examples or model weight updates. During inference, the agent: 1) Identifies ambiguous field-mapping attempts. 2) Generates targeted web-search queries to gather external evidence. 3) Applies a confidence-based reward to iteratively refine its mappings. To demonstrate this concept, we converted Microsoft Defender for Endpoint logs into a common schema. Our method increased mapping accuracy from 56.4\%(LLM-only) to 72.73\%(RAG) to 93.94\% over 100 iterations using GPT-4o. At the same time, it reduced the number of low-confidence mappings requiring expert review by 85\%. This new approach provides an evidence-driven, transparent method for solving future industry problems, paving the way for more robust, accountable, scalable, efficient, flexible, adaptable, and collaborative solutions.


AI malware could beat Microsoft Defender up to 8 percent of the time

PCWorld

According to hackers at this year's upcoming Black Hat conference, some of the newest stuff can defeat Microsoft Defender (the default security suite for a billion or two Windows machines) up to 8 percent of the time. Dark Reading (via Tom's Hardware) reports that a security researcher will present the system at the Black Hat security conference in Las Vegas next month. Kyle Avery of Outflank will reportedly show off a lightweight language model designed specifically to evade Microsoft Defender, the free built-in security for Windows 10 and Windows 11. Eight percent might not seem alarming, and it's not as if this would be the first time Defender was defeated. But it would be a huge leap forward in AI-powered malware's core capability, an order of magnitude more reliably dangerous than the malware you can "vibe code" with current models.


Improving AI-based defenses to disrupt human-operated ransomware - Microsoft Security Blog

#artificialintelligence

Microsoft's deep understanding of human-operated ransomware attacks, which are powered by a thriving cybercrime gig economy, continuously informs the solutions we deliver to protect customers. Our expert monitoring of threat actors, investigations into real-world ransomware attacks, and the intelligence we gather from the trillions of signals that the Microsoft cloud processes every day provide a unique insight into these threats. For example, we track human-operated ransomware attacks not only as distinct ransomware payloads, but more importantly, as a series of malicious activities that culminate in the deployment of ransomware. Detecting and stopping ransomware attacks as early as possible is critical for limiting the impact of these attacks on target organizations, including business interruption and extortion. To disrupt human-operated ransomware attacks as early as possible, we enhanced the AI-based protections in Microsoft Defender for Endpoint with a range of specialized machine learning techniques that find and swiftly incriminate – that is, determine malicious intent with high confidence – malicious files, processes, or behavior observed during active attacks.


Discover how you can innovate anywhere with Azure Arc

#artificialintelligence

Welcome to Azure Hybrid, Multicloud, and Edge Day--please join us for the digital event. Today, we're sharing how Azure Arc extends Azure platform capabilities to datacenters, edge, and multicloud environments through an impactful, 90-minute lineup of keynotes, breakouts, and technical sessions available live and on-demand. Now you can build, train, and deploy your machine learning models right where the data lives, such as your new or existing hardware and IoT devices. When I talk with customers, one of the things I hear most frequently is how new cloud-based applications drive business forward. And as these new applications are built, they need to take full advantage of the agility, efficiency, and speed of cloud innovation. However, not all applications and infrastructure they run on can physically reside in the cloud.