<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Activity Reports showing malware category for a Microsoft website? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-reports-showing-malware-category-for-a-microsoft/m-p/322024#M82394</link>
    <description>&lt;P&gt;My guess would be that the following signature update for C2 signatures:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;generic:007896376966807894.windows-updates-service.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That was deployed in 3311 and subsequently removed in 3312 is a little bit too off and caught more traffic than intended. If you haven't already, update to 3312 and the issue should go away.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2020 22:33:41 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-04-09T22:33:41Z</dc:date>
    <item>
      <title>User Activity Reports showing malware category for a Microsoft website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-reports-showing-malware-category-for-a-microsoft/m-p/321582#M82301</link>
      <description>&lt;P&gt;On our User Activity Reports, I'm seeing windowsupdate.com with a block-url action and malware category classification.&amp;nbsp; The URL appears to be valid.&amp;nbsp; Does anyone have an idea why this would be happening?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 15:08:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-reports-showing-malware-category-for-a-microsoft/m-p/321582#M82301</guid>
      <dc:creator>AnniesIT</dc:creator>
      <dc:date>2020-04-08T15:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Reports showing malware category for a Microsoft website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-reports-showing-malware-category-for-a-microsoft/m-p/322024#M82394</link>
      <description>&lt;P&gt;My guess would be that the following signature update for C2 signatures:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;generic:007896376966807894.windows-updates-service.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That was deployed in 3311 and subsequently removed in 3312 is a little bit too off and caught more traffic than intended. If you haven't already, update to 3312 and the issue should go away.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 22:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-reports-showing-malware-category-for-a-microsoft/m-p/322024#M82394</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-09T22:33:41Z</dc:date>
    </item>
  </channel>
</rss>

