
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
A newly disclosed detection gap in Microsoft Defender XDR could be causing security teams to silently miss command-and-control (C2) traffic and other malicious external communications, according to researcher Alex Teixeira. The flaw centers on how Defender’s DeviceNetworkEvents table classifies IPv4-mapped IPv6 addresses, a common but overlooked artifact of dual-stack networking on Windows systems. Many detection […]
The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on Cyber Security News.