pwshub.com

Microsoft blows up admins' inboxes with fake malware alerts

Updated Many administrators have had a trying Monday after getting spammed out with false malware reports by Microsoft.

In the last hour the Microsoft 365 service center put out an alert on Xitter, oddly, even before sending out the customary 365 Service Alert email, users complained. Others pointed out that the issue was flagged on Reddit more than two hours before Microsoft got around to alerting customers.

"We're investigating an issue in which some users' email messages may be incorrectly flagged as malware and quarantined. More info can be found in the admin center under EX873252," Microsoft posted.

"We identified an issue affecting our malware detection systems. We've implemented a mitigation to unblock legitimate emails that were mistakenly quarantined. The replay of impacted emails is in progress."

  • Choose Your Own Adventure with Microsoft 365
  • Multiple flaws in Microsoft macOS apps unpatched despite potential risks
  • Microsoft to stop telling investors about peformance of server products
  • Microsoft services partly down Down Under for Kiwi users

For the moment it seems admins will have to manually unblock legitimate emails. Given the volume of material, and the need for care not to let actual malware through, this might take some time. It also appears that the original EX873252 article has been taken down, although you can see it here.

The issue appears to have kicked off around 0900 ET (1300 UTC), and Britain's National Health Service issued an alert a few hours later. Redmond has reportedly said it is fixing the problem but, while many are reporting the flood of false positives has eased, it doesn't appear that the issue is fully resolved as yet.

One amateur sysadmin sleuth suggests it's down to an issue with the Microsoft Defender Threat Explorer and the PowerShell Get-QuarantineMessage cmdlet.

We'll update this piece when there's a solid statement from Microsoft. ®

Updated at 2000 UTC on August 26

Microsoft claims the 365 issue is fixed in 99% of cases. "Telemetry shows over 99% of impacted emails have been unblocked and automatically replayed," it Xeeted.

Source: theregister.com

Related stories
2 weeks ago - Loads of governance issues to worry about, and the chance it might spout utter garbage Microsoft has published a Transparency Note for Copilot for Microsoft 365, warning enterprises to ensure user access rights are correctly managed...
1 month ago - Windows giant continues march away from on-prem and into a cloudy future Microsoft is to discontinue the Microsoft Action Pack and Microsoft Learning Pack on January 21, 2025, sending partners off to potentially pricier and cloudier...
2 weeks ago - Web services celebrates 'leader' designation for Q Developer Amazon Web Services on Tuesday took a moment to pat itself on the back for being thought of inside the box, specifically, the upper right-hand square that's part of Gartner's...
2 weeks ago - I spoke with the tech pioneer about his new Netflix docuseries that touches on artificial intelligence, global warming and more.
6 days ago - I spoke with the tech pioneer about his new Netflix docuseries that touches on the future of AI, global warming and more.
Other stories
23 minutes ago - Yoga is a powerful tool that can help you sleep better. These are the top three yoga poses you should start using tonight.
23 minutes ago - Why You Can Trust CNET Our expert deal-hunting staff showcases the best price drops and discounts from reputable sellers daily. If you make a...
23 minutes ago - The Amazon Fire 7 Kids Pro tablet is now just $45 at Woot, and Prime Members can unlock free shipping for extra savings to boot.
24 minutes ago - Embracing exercise when you'd really rather not is easier than you think. Here's how to do it.
24 minutes ago - Microsoft Office licenses can be expensive, but this limited-time StackSocial deal lets you snag one for a paltry $25.