Did you read that virtual is no longer supported.
I didn’t know that!
And why wasn’t it discontinued and removed from the room?
Because I am not a mod or staff that why
It did not detect on my end you got issues
Hey everyone, I hosted a nearly 4-hour livestream to showcase the new version of CIS, find out if anything changed beyond the name and terms like HIPS and EDR, and put CIS to the test against 299 malware samples—ranging from zero-days to “one-day” exploits.
Here are the tests and results:
-
CIS updates + CIS 2027 vs. the old exploit: CIS had been updated and protected against the PoC, even with all its modules disabled except for Auto-Containment (I mean all of them, even script analysis);
-
CIS 2027 vs. 299 malware samples (without Auto-Containment or Cloud Analysis): Its AV identified just over 100 samples, while the rest fluctuated between execution and offline identification;
-
CIS 2027 vs. the same 299 malware samples (without the antivirus module, but with Auto-Containment + Firewall + WebLookUp): 298 samples were isolated by Auto-Containment and 1 executed; however, when I uploaded that file to VirusTotal, no engines detected a threat. I ran some checks, and it appears the file is either legitimate, an incomplete malware sample (the type that needs to download a payload but fails to complete that step, even without CIS), or simply a corrupted/incomplete file.
It seems that the old exploit was updated and the new version can obliterate cis 2027 containment…
Livestream link: https://www.youtube.com/live/RAPQk6XDtzw (In pt-BR only. I don´t know if Youtube already made the automatic subs for this live)
I only had an Edge registry entry that was detected. CCE can have false positives and you need to ensure you have a full backup before using that tool.
Blocked application rules do not work if cloudflare warp desktop application is in “connected” state.
Now my choice is to either use comodo firewall or cloudflare warp.
Is there no way to use them both together
I installed over Premium version 12.3.4.8162. Installation appeared as normal but it didn’t ask for a reboot as it normally does.
Widget says I have to restart.
Restarted and nothing has changed, v12.3.4.8162 still installed.
Did this twice and gave up.
All the files in COMODO Internet Security folder are the same, none updated. One new file exists which is SecurityProductInformation.ini. It says:
[Products]
Name=COMODO Internet Security 2025
Company=Comodo Security Solutions Inc
PathToSignedReportingExe=C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Version=12.3.4.8162
Environment=Both
Runtime_platform=ALL
Upgrade=FALSE
I am updating Premium for Premium version.
Exactly the same with my laptop.
Working through logs and monitoring files seems to show ProgramData\Comodo Downloader folder deleted when installer finishes, so no update to run on restart.
Appreciated if you can test samples like white .exe execute file load malware .all file.
The issue with Comodo’s sandbox persists; this PoC still manages to bypass auto-containment.
Essa imagem e do forum malwartips LINK: https://malwaretips.com/threads/introducing-comodo-internet-security-2027-v12-4-0-8170.142452/page-3
Though he said it passed the old POC test and is yet to test the new one.Has he run the test since with the updated POC? Time stamp in video?
(MT Post)
“1) CIS updates + CIS 2027 vs. the old exploit: CIS had been updated and protected against the PoC, even with all its modules disabled except for Auto-Containment (I mean all of them, even script analysis);”
“Now, I’m just waiting to see if Loyiza will be kind enough to send me her new PoC/exploit so I can test it in a future livestream against the new CIS 2027”
She likely updated the new PoC, thereby bypassing Sandboxie.
It is clear that if Comodo releases an update after five years, another PoC will be created to bypass it.
What Comodo needs to do is fix the issue properly; it seems they haven’t, as proven by her test.
She managed to bypass Comodo’s Sandboxie in less than 24 hours—that’s incredible. Won’t the Comodo team fix this correctly?
We need to stay protected!
Yes, the PoC is the most up-to-date version.
Well then it passed according to the message above.
Maybe there’s a way to create a containment rule to sandbox all untrusted DLLs in appdata/programfiles or temp ![]()
It was approved just as the video was being released, but it was later discovered that a new version of the PoC existed—one that once again bypassed the mitigation.
If there is a rule or any other method to resolve this issue, please share the step-by-step instructions so everyone can implement them and run the tests again; if you know how, please let us know.
Thanks—right now, there is no way to fix it because the self-mitigation has been bypassed.
I might be getting on people’s nerves now, but here we go again. The discussions here and on MalwareTips don’t exactly inspire confidence. The problem lies not with the people discussing it, but with the software—the program itself. This constant back-and-forth really implies just one thing: there are more reliable programs out there—ones where there are no doubts regarding updates and security, just things like name changes. Cruelsister gets mentioned negatively on MalwareTips; she’ll likely try to put a positive spin on this latest mess.
And yet, whenever I scan my PC with various scanners, it comes up clean—and has done so for over two decades. As a complete layperson, you simply have to rely on what the pros or the most well-informed people have to say. But my own experiences with Comodo are probably the least informative of all. My own experiences with Comodo are probably the least informative of all; I can only draw my own conclusions from everything. Once again!
There are two ways to stop being a nuisance.
![]()
A very big thanks for the release.
Will it be possible to install it via CIS internal updater?
I have the same question; I have several machines with CIS, and I want to update using the built-in CIS updater to avoid the hassle of uninstalling and reinstalling on every machine.
I executed both without any problems.

