news.mlab.sh
Back to the feed
vulnerability

NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

High
Summary

A zero-day vulnerability in Microsoft Defender, stemming from a flaw in how the system handles code from ZCodeChina's AI model, is allowing attackers to bypass security measures. This represents a significant risk for organizations relying on Microsoft's security software, as it effectively renders Defender obsolete against certain attacks. The vulnerability highlights a growing concern about the security of AI-generated code and its potential to be exploited.

A zero-day vulnerability has been discovered in Microsoft Defender, allowing attackers to bypass the security software. This flaw originates from ZCodeChina’s AI model, specifically a Grok-esque security flaw that enables attackers to inject malicious code. The vulnerability was highlighted by an engineer, leading to a surprise bill for a Register reader who was impacted by the issue. Microsoft’s on-prem SharePoint has also been found to be vulnerable, despite previous patching attempts failing to address the underlying problem. This incident underscores the challenges of maintaining robust security in an era of increasingly sophisticated AI-generated code and the difficulty of keeping security software consistently up-to-date.

Read the full article at The Register