-
Notifications
You must be signed in to change notification settings - Fork 115
[Bug]: Significant increase in False Positives (July 2026) #167
Open
Description
Required confirmations before submitting
- I can reproduce this issue on the latest released version of Check.
- I have searched existing issues (both open and closed) to avoid duplicates.
- I am not requesting general support; this is an actual bug report.
Issue Description
There's been an increase this week in Check detecting false positives.
On 2026年07月06日 we had "https://id.trimble.com/": Form action "https://id.trimble.com" does not contain login.microsoftonline.com.
Today (2026年07月08日) we had the following:
- "https://signin.ebay.co.uk": Form action "https://signin.ebay.co.uk/signin/s" does not contain login.microsoftonline.com
- "https://auth.services.adobe.com": Form action "https://auth.services.adobe.com/en_GB/index..." does not contain login.microsoftonline.com, with this "Phishing Indicators Found: Parse error - check browser console"
- a "Suspicious Microsoft 365 Login Page" banner appears in the CyberDrain Check-Chat Discord channel: https://discord.com/channels/905453405936447518/1418612449170690219 - with the Displayed Reason: SUSPICIOUS CONTENT DETECTED: Suspicious phishing indicators detected: phi_021_suspicious_url_structure, and Detected Indicators:
- url_structure: Suspicious URL structure with long random strings in path segments (before query parameters)
Extension Version
1.2.0
Rules Version
1.2.4