<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Memory Corruption Exploit Alerts - Incidents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/memory-corruption-exploit-alerts-incidents/m-p/440150#M1137</link>
    <description>&lt;P&gt;Hello LiveCommunity, I wondered if any others are seeing a very high number of recently created (in the last few hours) "Memory Corruption Exploit" alerts in Cortex XDR?&lt;BR /&gt;&lt;BR /&gt;Beginning around 1015 Pacific this morning (11 Oct) thru as recent at 1518 Pacific, 11 Oct there has been numerous alerts fired across many different Workstations&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing many different Initiator Paths such as:&lt;BR /&gt;C:\Windows\System32\spoolsv.exe&lt;/P&gt;&lt;P&gt;C:\Program Files\Google\Chrome\Application\chrome.exe&lt;/P&gt;&lt;P&gt;C:\Windows\System32\RuntimeBroker.exe&lt;/P&gt;&lt;P&gt;C:\Program Files (x86)\Internet Explorer\iexplore.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought perhaps it was a Content update, but does not look like there has been a new content update since sometime last week.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Oct 2021 22:37:41 GMT</pubDate>
    <dc:creator>KRisselada</dc:creator>
    <dc:date>2021-10-11T22:37:41Z</dc:date>
    <item>
      <title>Memory Corruption Exploit Alerts - Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/memory-corruption-exploit-alerts-incidents/m-p/440150#M1137</link>
      <description>&lt;P&gt;Hello LiveCommunity, I wondered if any others are seeing a very high number of recently created (in the last few hours) "Memory Corruption Exploit" alerts in Cortex XDR?&lt;BR /&gt;&lt;BR /&gt;Beginning around 1015 Pacific this morning (11 Oct) thru as recent at 1518 Pacific, 11 Oct there has been numerous alerts fired across many different Workstations&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing many different Initiator Paths such as:&lt;BR /&gt;C:\Windows\System32\spoolsv.exe&lt;/P&gt;&lt;P&gt;C:\Program Files\Google\Chrome\Application\chrome.exe&lt;/P&gt;&lt;P&gt;C:\Windows\System32\RuntimeBroker.exe&lt;/P&gt;&lt;P&gt;C:\Program Files (x86)\Internet Explorer\iexplore.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought perhaps it was a Content update, but does not look like there has been a new content update since sometime last week.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 22:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/memory-corruption-exploit-alerts-incidents/m-p/440150#M1137</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2021-10-11T22:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Memory Corruption Exploit Alerts - Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/memory-corruption-exploit-alerts-incidents/m-p/440391#M1140</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, I would recommend opening a support case if you have concerns that this being a false positive. The support team can assist you to further investigate what behavior changed, in the meantime, you have the option to suppress these alerts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 21:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/memory-corruption-exploit-alerts-incidents/m-p/440391#M1140</guid>
      <dc:creator>tvilas</dc:creator>
      <dc:date>2021-10-12T21:57:49Z</dc:date>
    </item>
  </channel>
</rss>

