False malicious activities / windows update

12346»

All Replies

  • st3213
    st3213 Posts: 9  Freshman Member
    First Comment Friend Collector First Anniversary
    edited February 2023

    unfortunately, the issue is still prevalent on our USG 500 flex. False positives still happen every month on MS patch day! It often involves some kind of dotnet-runtime-file, today it was the Update KB5023288. The Hash is 28F846B09CB2CFE30ADDFC2731853AF9.

    You really should look at this - adding files to the allow list every month by hand or posting here is not a sustainable solution.

    Thank you very much.
  • Vagabound
    Vagabound Posts: 30  Freshman Member
    First Comment Friend Collector First Anniversary
    edited February 2023
    Here is the same procedure every month on Windows Patchday with a USG Flex 200. It is getting tedious to feed the white list every month.


  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    HI @Vagabound,

    Sorry for inconvenience caused. It is in our roadmap, and the solution would be ready at  the end of April.
  • Dexta
    Dexta Posts: 14  Freshman Member
    First Comment Friend Collector First Anniversary
    Vagabound said:
    Here is the same procedure every month on Windows Patchday with a USG Flex 200. It is getting tedious to feed the white list every month.



    At least you have a whitelist ;) On Nebula you don't even have one. So we are stuck with installing by hand or disable the sandboxing feature.

Security Highlight