I actually opened a topic on this a week ago or so in this community forum, have not seen any responses of others receiving, found this post by searching Google for one of the IP’s I was seeing and Microsoft wimgapi LoadIntegrityInfo heap buffer overflow attempt. Been seeing these type of alerts for a few weeks now on a few of our MX‘s, the source IP are from Microsoft CDN, like Alkamai, not whitelisted them yet, seeing blocks to random PC’s, not doing windows 11 updates just normal month-to-month patches..? I’ve checked out all the source IP’s I’m seeing and they’re all clean via virus total and Cisco Talos, so not sure what to do, assuming false positives but man there’s a lot of these alerts.
... View more