logo

Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates

ID: 8d8a1ade-9214-598b-8c57-49ad2f6373a2

STIX ID: report--8d8a1ade-9214-598b-8c57-49ad2f6373a2

Feed Name: TechRepublic Security

Threat Score
45/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ken Underhill

...
...

A Microsoft Defender signature update introduced detections for Trojan:Win32/Cerdigent.A!dha that were overly broad and flagged legitimate DigiCert root certificates as malicious, causing deletions from Windows trust stores and operational disruption. The detections were tied to Microsoft’s response to a DigiCert code-signing certificate compromise (including certificates linked to the Zhong Stealer campaign); Microsoft updated the alert logic and released a patch. The report emphasizes risks from automated defenses, recommends updating Defender, validating certificate stores, centralizing certificate management, and improving monitoring and response procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.