Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware
ID: 787c3dd4-0680-5fad-be19-67b2fe64eab2
STIX ID: report--787c3dd4-0680-5fad-be19-67b2fe64eab2
Feed Name: cybersecurityNews.com
A Microsoft Defender antimalware signature update around April 30, 2026 produced a false positive (Trojan:Win32/Cerdigent.A!dha) that quarantined two legitimate DigiCert root certificates from the Windows trust store, risking widespread SSL/TLS validation and code-signing failures. The report outlines detection details (including certificate thumbprints), administrative hunting and verification commands, community reporting, and Microsoft’s corrective definition update (version .430) that restored certificates and mitigated the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
