<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>False-Positive on CuraSec</title><link>https://curasec.metacog.co.kr/tags/false-positive/</link><description>Recent content in False-Positive on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/false-positive/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Defender for Office 365 false-positives block Google links</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-microsoft-defender-flags-legitimate-google-search-links-as-m/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-microsoft-defender-flags-legitimate-google-search-links-as-m/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your org uses Defender for Office 365, check whether Safe Links is blocking legitimate Google URLs and configure allow-list exceptions or monitor Microsoft&amp;rsquo;s investigation for a fix.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Expect a spike in user-reported blocked links; tune alert triage to deprioritize Safe Links hits on google.com domains until Microsoft issues a resolution.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft: Ignore False 'Antivirus Turned Off' Alerts After Defender Update</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-microsoft-asks-users-to-ignore-antivirus-is-turned-off-error/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-microsoft-asks-users-to-ignore-antivirus-is-turned-off-error/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Defender Antivirus false-positive after recent update may trigger compliance alerts or monitoring noise; no patch or configuration change needed, just awareness that the UI error is benign until Microsoft releases a fix.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Suppress or contextually tune alerts for Defender &amp;lsquo;antivirus turned off&amp;rsquo; events caused by this update so analysts aren&amp;rsquo;t flooded with false positives; document the known-issue window to avoid masking real AV-disabling activity.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>