<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft-Defender on CuraSec</title><link>https://curasec.metacog.co.kr/tags/microsoft-defender/</link><description>Recent content in Microsoft-Defender on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/microsoft-defender/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft: Ignore False 'Antivirus Turned Off' Alerts After Defender Update</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-microsoft-asks-users-to-ignore-antivirus-is-turned-off-error/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-microsoft-asks-users-to-ignore-antivirus-is-turned-off-error/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Defender Antivirus false-positive after recent update may trigger compliance alerts or monitoring noise; no patch or configuration change needed, just awareness that the UI error is benign until Microsoft releases a fix.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Suppress or contextually tune alerts for Defender &amp;lsquo;antivirus turned off&amp;rsquo; events caused by this update so analysts aren&amp;rsquo;t flooded with false positives; document the known-issue window to avoid masking real AV-disabling activity.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>ShieldBreak PoC Bypasses Defender Patch, Achieves SYSTEM Privilege</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-byp/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-byp/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Public PoC on GitHub means the original CVE-2026-50656 patch is insufficient, but EPSS 0.11 and no KEV listing indicate no confirmed active exploitation yet. Monitor Microsoft&amp;rsquo;s advisory for an updated patch and apply it immediately when released; in the interim, audit for any unexpected SYSTEM-level Defender process activity.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The public PoC provides enough technical detail to build behavioral detections before in-the-wild exploitation begins. Develop signatures for anomalous Microsoft Defender process privilege escalation patterns from the PoC and queue for tuning once exploitation is confirmed.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-50656 — CISA KEV: not listed, EPSS 0.11, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Defender auto-isolates ransomware endpoint in 128 seconds</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-128-seconds-to-disruption-microsoft-defender-stops-ransomwar/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-128-seconds-to-disruption-microsoft-defender-stops-ransomwar/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The case illustrates how automated endpoint isolation can compress ransomware dwell time to under three minutes; worth reviewing your own EDR auto-containment thresholds against this benchmark.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>