Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links
Service Disruption
Summary
Hide ▲
Show ▼
Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning prompts. The issue is tied to an inaccurate security classification and is generating related alerts in Microsoft Sentinel and the Defender portal.
Related Happenings
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/Service
H score11
First: 31.08.2026 11:29
Last: 31.08.2026 11:29
Sources 1
About this happening:
Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/ServiceAbout this happening: Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch Release
H score32
First: 17.06.2026 20:36
Last: 17.06.2026 20:36
Sources 1
About this happening:
Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch ReleaseAbout this happening: Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Latest development: 09.07.2026 11:48
Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.
Timeline
-
02.09.2026 13:30 2 articles · 2h ago
Microsoft investigates Safe Links blocking legitimate Google search links
Initial DisclosureMicrosoft is investigating a Defender for Office 365 Safe Links issue in which legitimate Google search links are incorrectly classified as malicious, causing users to see "Opening this website might not be safe" warnings when opening the blocked URLs. Microsoft also says IT administrators may see related alerts and incidents in Microsoft Sentinel and the Defender portal while it works to correct the misclassification.
Show sources
- Microsoft Defender flags legitimate Google search links as malicious — www.bleepingcomputer.com — 02.09.2026 13:29
- Microsoft Defender flags legitimate Google search links as malicious — www.bleepingcomputer.com — 02.09.2026 13:29