Microsoft Defender XDR False Positive Leads to Massive Data Leak of 1,700+ Sensitive Documents
ANY.RUN research identified a large-scale data leak event triggered by a false positive in Microsoft Defender XDR. The security platform incorrectly flagged benign files as malicious, leading to their automatic submission to ANY.RUN’s public sandbox for analysis. As a result, over 1,700 sensitive documents were uploaded and indexed publicly. The leak, which involved corporate data […] The post Microsoft Defender XDR False Positive Leads to Massive Data Leak of 1,700+ Sensitive Documents appeared first on Cyber Security News.

ANY.RUN research identified a large-scale data leak event triggered by a false positive in Microsoft Defender XDR. The security platform incorrectly flagged benign files as malicious, leading to their automatic submission to ANY.RUN’s public sandbox for analysis. As a result, over 1,700 sensitive documents were uploaded and indexed publicly.
The leak, which involved corporate data from hundreds of companies, has raised alarm bells about the risks of misclassification in threat detection systems and the unintended consequences of user behavior in response to such errors.
The incident began when Microsoft Defender XDR, a widely used advanced threat protection platform, mistakenly flagged legitimate Adobe Acrobat Cloud links specifically URLs starting with acrobat[.]adobe[.]com/id/urn:aaid:sc:—as malicious.
According to a ANYRUN report shared with Cyber Security News , this error triggered a sudden influx of Adobe Acrobat Cloud links being uploaded to their sandbox for analysis.