Microsoft disclosed that a flawed Defender for Endpoint on Linux update could leave antivirus protection disabled after an upgrade or reinstall followed by a reboot. The issue affected platform builds 101.26042.0000 through 101.26042.0009, creating a silent gap in active protection on impacted Linux systems until administrators verified agent health or applied a corrected release. Microsoft removed the affected builds from the production channel and said the disabled-service problem is remediated in version 101.26042.0011.
A second defect in the same update line caused installation failures on FIPS-enabled Red Hat Enterprise Linux 8 and 9 systems, preventing those hosts from moving off their previous version. Microsoft said environments using Defender for Servers with Defender for Cloud and MDE integration may have received the affected Linux extension automatically. The FIPS-related issue is fixed in 101.26052.0011 and later, and administrators were urged to upgrade directly to the corrected builds and confirm Linux endpoint protection is running after reboot.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft removed Defender for Endpoint on Linux builds 101.26042.0000 through 101.26042.0009 from the production channel after the disabled-service issue was identified. The affected builds had briefly left some Linux servers without active protection after reboot.
Microsoft remediated the disabled-service issue with build 101.26042.0011 and advised customers to upgrade directly to that version. It also fixed the FIPS-related installation problem in version 101.26052.0011 and later.
Microsoft disclosed that Linux platform builds 101.26042.0000 through 101.26042.0009 could leave the Defender service disabled after an upgrade or reinstall followed by a reboot. It also disclosed that the 101.26042.x update could fail on FIPS-enabled Red Hat Enterprise Linux 8 and 9 systems, leaving them on their previous version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetheregister.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.