惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
J
Java Code Geeks
Martin Fowler
Martin Fowler
Microsoft Azure Blog
Microsoft Azure Blog
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
博客园 - 【当耐特】
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
G
Google Developers Blog
博客园 - 三生石上(FineUI控件)
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
大猫的无限游戏
大猫的无限游戏
罗磊的独立博客
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
博客园 - 司徒正美

Heimdal Security Blog

Slow is a design principle, not a delay AI adoption that pays off is built around keeping humans in the driver's seat Phishing in 2026. Latest statistics and analysis Shift Browser is signed adware that fingerprints your endpoint before it drops payload 6 ThreatLocker alternatives that should make your shortlist 50+ insider threat statistics for 2026 The Planting Seeds philosophy. Selling into schools takes years, not quarters What the DfE's cyber security update means for multi-academy trusts 9 Proofpoint alternatives. Pros & cons of the leading options The risk awareness radar. A superpower every MSP needs to train How Heimdal grew from a bold idea into a global cybersecurity platform Tools Change. Teach People How to Keep Up The 4 best managed EDR service suppliers (and how to choose) How to choose the best SOC platform in 2026 (and our top 4) MediaArena malvertising: why a quarantine isn't the end of the incident Top 6 Managed Detection and Response Providers Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors How to scale your patches without scaling your team (the patch wave) AI didn't break patching. It showed us patching was already broken. Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes How Dynamic Defense shuts an attacker out without shutting down the business Static security has run out of road. The case for Dynamic Defense Breaking the MSP Echo Chamber: The Power of Community How attackers built a RAT on a Windows machine using its own .NET compiler Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Your Next Insider Threat May Be an AI Coworker The OSI Model and Its Two Missing Layers Heimdal® Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification
Heimdal data reveals MediaArena adware completes persiste...
Madalina Popovici · 2026-07-30 · via Heimdal Security Blog

London, UK, 30 July 2026 New data from Heimdal’s telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments.

MediaArena is a browser-modifier adware family that Microsoft has tracked since 2023. It is low-severity, and that is what makes the finding notable. Even a nuisance-grade detection can finish establishing persistence before antivirus intervenes.

The malvertising cluster spreading it has been publicly documented since March and was analysed by Compass Apex Security in April. It reaches victims through fake “free AI tool” ads.

Using its own telemetry from live client environments, Heimdal measured the timeline of a MediaArena infection. The adware finished writing its persistence mechanism to disk 21 seconds after execution. Microsoft Defender’s quarantine did not finish until 29 seconds, a full eight seconds after the infection had already taken hold.

This measurement comes from direct observation of Heimdal’s own customer base, not from a lab or a sandbox.

The pattern is not an isolated case. Heimdal has observed the same sequence, persistence completing before quarantine finishes, across more than 40 client environments in recent days. In the case Heimdal timed, signature-based detection then took roughly 78 days to catch up, leaving the browser hijacker running for around eleven weeks.

“We timed a MediaArena infection and the persistence was on disk before the quarantine even finished. The alert isn’t wrong, it’s just late. By the time it fires, the adware has already done what it came to do, so a team that stops at ‘quarantined’ is working from an incomplete picture,”

said Alexandru Gurgu, Threat Intelligence Security Analyst at Heimdal.

The takeaway for security teams is direct. A quarantine alert is not proof that an endpoint is clean. For MediaArena, the alert may simply mark the moment detection caught up, not the moment the threat was stopped.

Heimdal recommends treating a MediaArena quarantine alert as the start of an investigation, not its conclusion, and checking affected endpoints directly for persistence artefacts.

Read the full report here: https://heimdalsecurity.com/blog/media-arena-malvertising-report/ 

About Heimdal

Heimdal is a global cybersecurity provider offering a unified security and compliance platform across endpoint, identity, email, network, and access security. More than 17,000 customers and 1,500 MSPs in over 40 countries use its 12-plus integrated products to prevent threats, detect breaches, and automate response. 

Media contact

Madalina Popovici

Media Relations Manager, Heimdal

mpo@heimdalsecurity.com

If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube for more cybersecurity news and topics.

Author Profile

linkedin icon

Madalina, a seasoned digital content creator at Heimdal®, blends her passion for cybersecurity with an 8-year background in PR & CSR consultancy. Skilled in making complex cyber topics accessible, she bridges the gap between cyber experts and the wider audience with finesse.