Microsoft: DigiCert Root Certificates Are Malware? Censys in SOC Triage
ID: b7c81731-d9a6-5ab8-bc01-2f1f38759228
STIX ID: report--b7c81731-d9a6-5ab8-bc01-2f1f38759228
Feed Name: Censys Blog
Threat Score
On May 3, 2026 Windows Defender repeatedly flagged two DigiCert root certificates as a Trojan, leading to quarantines of root-store entries and widespread alerts; Censys-based triage showed the certificates were legitimate root CAs (not revoked and trusted by major stores) and Microsoft resolved the false positives with a Security Intelligence update (1.449.430.0+), illustrating the importance of authoritative certificate context in SOC investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
