If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, […]
The post MediaArena malvertising: why a quarantine isn’t the end of the incident appeared first on Heimdal Security Blog.
Read the original article: