Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links.

Sergiu Gatlan BleepingComputer
安全新闻钓鱼攻击零日漏洞

Microsoft Defender

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly flag legitimate Google search links as malicious.

The company first acknowledged the incident (tracked under MO1465962) at 10:30 AM UTC and says affected users are seeing "Opening this website might not be safe" warnings when trying to open the blocked hyperlinks.

According to a service alert seen by BleepingComputer, the issue is caused by an inaccurate security classification, and copying the links and pasting them directly into a browser will not bypass the warning.

Microsoft also warned IT administrators that they may see alerts in the Microsoft Sentinel security information and event management (SIEM) solution and the Defender portal regarding this ongoing incident.

"Microsoft Defender for Office 365 Safe Links may block the opening of Google search links (URLs), identifying them as malicious. In addition, admins may receive related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel as a result of these detections," Microsoft said.

"We've determined that an inaccurate security classification is causing legitimate Google search URLs to be incorrectly identified as malicious, resulting in Microsoft Defender for Office 365 Safe Links blocking access to affected links. We're working to correct the misclassification to remediate impact."

Safe Links blocks malicious links used in phishing and other attacks by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs in email messages, Teams, and Office 365 apps in organizations with a Defender for Office 365 license.

While Microsoft has yet to disclose which regions are impacted or how many customers are affected, it has classified it as an advisory, which is typically used to describe service issues involving limited scope or impact.

Microsoft has addressed similar false positive issues over the last several years that resulted in links and messages being incorrectly tagged as malicious or quarantined.

For instance, last year, an Exchange Online bug caused a machine learning model to mistakenly flag emails from Gmail accounts as spam, while another one caused anti-spam systems to quarantine some users' legitimate emails.

More recently, in February, an Exchange Online issue prevented users from sending or receiving emails and flagged legitimate messages as phishing, quarantining them.

Microsoft is also working to address a massive, widespread Microsoft 365 outage causing authentication issues, service delays and failures, connection problems, and other issues.

Related Articles:

Microsoft asks users to ignore 'Antivirus is turned off' errors

Microsoft Teams now lets admins block external bots from meetings

Microsoft fixes known issue causing Windows Defender crashes

Microsoft working on Defender patch for ShieldBreak zero-day

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges