u/ITinDC

MS Defender False Positive? "An active 'Wacatac' malware was blocked"

MS Defender False Positive? "An active 'Wacatac' malware was blocked"

Hi all - received a deluge of alerts this morning from MDE across a few client systems and I think it was an update file related to Screenconnect. Did anyone else experience this today? It appears to be a false positive but I wanted to check with other folks. Goes without saying that my cloud instance was not compromised in any way, so I assume this is something related to an auto-update of the client.

https://preview.redd.it/p2rlo2adbk5h1.png?width=1300&format=png&auto=webp&s=94f77094183359335a8e1029beb158c815d515cc

reddit.com
u/ITinDC — 5 days ago