Hi all,
Over the past month we have seen some of our users sending DNS queries for polyfill.io and cdn.polyfill.io.
Numerous articles such as this this one report that it has started spreading malicious code to visitors of websites that use this script.
I see that our checkpoint Anti-Virus blade is detecting this as protection - CeptBiro.TC.b726wWvx
The action has been a mix of detect and prevent - do you know why this is? Is there a way to change the action to always prevent? I searched for the protection under IPS protections but could not find it. I show the logs in the attached screenshot.
Thanks!