🟠 High  |  Source: The Register — Security


A recent update to Microsoft Defender for Endpoint (MDE) introduced two bugs affecting Linux systems: one caused the security service to fail on restart, leaving machines unprotected, and another blocked installation entirely on hardened Red Hat Enterprise Linux (RHEL) systems. Organisations relying on MDE as their primary endpoint detection and response tool on Linux infrastructure may have had a gap in coverage without realising it. Microsoft has since acknowledged the issues and is working on fixes.

Security Architect’s Take: Audit all Linux endpoints running MDE to confirm the service is actively running post-update — do not assume deployment equals protection. For hardened RHEL systems, verify installation succeeded and consider compensating controls such as enhanced logging or network-level detection until a confirmed fix is applied.

Original advisory: Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update