Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Microsoft Defender flags legitimate Google search links as malicious

Microsoft Defender flags legitimate Google search links as malicious

Scheduled Pinned Locked Moved Cybersecurity News
microsoftgoogle
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Microsoft is currently investigating a defect in Defender for Office 365 that is causing the security platform to incorrectly flag and block legitimate Google search links as malicious. The issue appears to affect users who click on organic search results, with Defender intercepting the navigation and presenting a warning page instead of allowing the request through.

    The problem does not seem to originate from the destination websites themselves, but rather from the way Google formats its redirect URLs. When a user clicks a search result, Google briefly routes the request through a tracking or forwarding prefix before sending the user to the final page. Defender for Office 365 is reportedly misreading this standard URL structure as a potential phishing or malware vector, leading to false positives.

    Microsoft has acknowledged the reports and stated that its team is actively investigating the root cause. While no workaround has been officially provided yet, administrators experiencing this issue have noted that temporarily disabling URL detonation or link safety checks in the security policy may restore normal functionality—though this is not recommended as a long-term solution due to the increased risk.

    Affected users are encouraged to monitor the Microsoft 365 admin center for service health notifications. The company has not yet specified a timeline for a permanent fix.

    • Affected service: Defender for Office 365 (link and URL protection features)
    • Trigger: Clicking legitimate Google search result links
    • Current status: Under active investigation by Microsoft
    • Temporary mitigation (not advised long-term): Disabling link safety checks in security policies

    Source: Unknown

    Has your organization encountered this false-positive issue with Defender for Office 365, and are you applying any interim filtering rules while waiting for the official patch?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World