Microsoft Defender Flaw Erased DigiCert Root Certificates and Paralyzed Windows Systems
ID: 1dba5a8d-1cfa-5584-8312-6a9ed658585e
STIX ID: report--1dba5a8d-1cfa-5584-8312-6a9ed658585e
Feed Name: securityonline.info
On April 2, 2026, DigiCert was breached via a phishing campaign targeting customer support, resulting in the exfiltration of sixty EV code‑signing certificates which were later used to sign malicious software; DigiCert revoked the compromised credentials. On April 30, 2026, a Microsoft Defender update erroneously flagged DigiCert root certificates as malicious and removed them from Windows Trusted Root stores, causing widespread TLS and application trust failures until Microsoft released corrective intelligence updates that restored the certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
