HomeSecurityMicrosoft: Exchange Online incorrectly flagged some emails as malware

Microsoft: Exchange Online incorrectly flagged some emails as malware

Microsoft is investigating an issue in Exchange Onlinethat incorrectly flagged some emails (with images) as malware and quarantined them.

Exchange Online malicious emails malware

" User emails containing images may be incorrectly flagged as malware and quarantined ," Microsoft said in a notice posted to the Microsoft 365 admin center.

The company said it was reviewing the evidence to find the cause and develop a plan to resolve the problem.

Microsoft noticed that the issue, tracked as EX873252, was widespread, after many system reported the problem in Exchange Online.

See also: Proofpoint: Hackers exploited bug to send phishing emails

“It appears to only affect our outbound traffic, specifically replies and forwards of previous external emails,” said an administrator.

“For us, it was both inbound and intra-org. Inbound alone I could deal with much easier. Also, they basically added our intra as inbound from what I saw in the tbr message header,” commented another.

Microsoft didn't say which areas were affected by this issue in Exchange Online, but mislabeling emails as malware is a significant problem. However, a few hours later, the company took some steps to move legitimate, harmless emails out of quarantine.

See also: sedexp: A Linux malware that remained hidden for two years

“We identified an issue detection systems malware. We have implemented measures to unblock legitimate emails that were accidentally quarantined,” Microsoft said. Later, the company said it had resolved the issue. “We have confirmed that this issue has been resolved after implementing a mitigation within the service. Telemetry shows that over 99% of affected emails have been unblocked,” the company said.

Microsoft: Exchange Online incorrectly flagged some emails as malware
Microsoft: Exchange Online incorrectly flagged some emails as malware

In October 2023, Microsoft faced a similar issue caused by an anti-spam rule that flooded Microsoft 365 administrators' inboxes with blind carbon copies (BCC) of outgoing emails, which were incorrectly marked as spam.

See also: Cthulhu Stealer: New info-stealer malware targets MacOS

The mislabeling of emails as malicious in Exchange Online highlights the importance of having a strong and proactive security. Addressing this issue promptly demonstrates Microsoft’s commitment to providing a secure email environment for users its. For their part, users should follow best practices and take advantage of the resources Microsoft provides to ensure their communications are protected. This includes staying informed of any security alerts or announcements from the company, implementing authentication , and regularly reviewing and updating security settings. By working together, Microsoft and its users can continue to maintain a secure email environment for everyone.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS