<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822116#M7507</link>
    <description>Me too.&lt;BR /&gt;Opened a Talos ticket, not the first so mine was auto-resolved. This isn't the first time they've flagged this file...&lt;BR /&gt;</description>
    <pubDate>Wed, 26 Apr 2023 11:44:05 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2023-04-26T11:44:05Z</dc:date>
    <item>
      <title>Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822107#M7505</link>
      <description>&lt;P&gt;This morning I started seeing retrospective quarantine failures for&amp;nbsp;Newtonsoft.Json.dll.&amp;nbsp; I see conflicting results when searching for this .dll.&amp;nbsp; The SHA is&amp;nbsp;SHA256:&amp;nbsp;c5c83bbc1741be6ff4c490c0aee34c162945423ec577c646538b2d21ce13199e&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 11:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822107#M7505</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2023-04-26T11:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822116#M7507</link>
      <description>Me too.&lt;BR /&gt;Opened a Talos ticket, not the first so mine was auto-resolved. This isn't the first time they've flagged this file...&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Apr 2023 11:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822116#M7507</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-04-26T11:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822170#M7508</link>
      <description>&lt;P&gt;Same issue.. first time popping up for us this morning.&lt;/P&gt;&lt;P&gt;C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2302.13003.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\Newtonsoft.Json.dll&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 12:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822170#M7508</guid>
      <dc:creator>BGKYandrewlafavers</dc:creator>
      <dc:date>2023-04-26T12:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822198#M7509</link>
      <description>&lt;P&gt;We have this alert going off as well. seeing this as an optional process for Autodesk, Snagit, and visual studios depending on user downloads/packages. eager to hear talos's response.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822198#M7509</guid>
      <dc:creator>nacryer</dc:creator>
      <dc:date>2023-04-26T13:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822210#M7510</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;We have investigated about this SHA-256 (&lt;SPAN&gt;c5c83bbc1741be6ff4c490c0aee34c162945423ec577c646538b2d21ce13199e&lt;/SPAN&gt;) and found that this is a benign file, hence this file should now be allowed on your environment.&lt;/P&gt;
&lt;P&gt;Since the file verdict was changed, the endpoints need some time to receive the last definitions, and may take up to 2 hours based on the policy configuration, other option is to update the policy and definitions manually from the Secure Endpoint UI.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Pedro M.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822210#M7510</guid>
      <dc:creator>pmedinac</dc:creator>
      <dc:date>2023-04-26T13:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822794#M7513</link>
      <description>&lt;P&gt;I'm still a Secure Endpoint newbie. We had the same alerts on a number of machines, and currently they are still showing in my inbox on the Secure Endpoint Dashboard under "Requires Attention". Are they supposed to get resolved automatically now that the file verdict was changed?&lt;/P&gt;
&lt;P&gt;I know I can just manually resolve them, but I would like to know whether or not they are supposed to disappear automatically.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 08:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822794#M7513</guid>
      <dc:creator>joljol</dc:creator>
      <dc:date>2023-04-27T08:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint flagged Newtonsoft.Json.dll as malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822929#M7514</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No , it will not be removed from Inbox. Think of Inbox as your "un-opened / un-answerd mail" in your Outlook. Something that needs your attention and your manual interaction. Inbox events are also directly related to the "Heat Map" on your Dashboard and percentage number under "Compromised" What you need to do is navigate in to Inbox select all events that you don't want to deal with or you already reviewed and click on&amp;nbsp; MARK RESOLVED. Those events will be then cleared out from the Heat MAP and Compromised % &lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Please note&lt;/STRONG&gt;: that you can still find these events under "Events" tab for history purpose also note that all events are automatically removed and cleared once they more than &lt;STRONG&gt;30 Days old&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 11:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-flagged-newtonsoft-json-dll-as-malicious/m-p/4822929#M7514</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-04-27T11:57:42Z</dc:date>
    </item>
  </channel>
</rss>

