logo

DigiCert compromise precedes widespread Microsoft Defender false positives

ID: 9e0195b4-5053-5472-aeb5-58e98953d00f

STIX ID: report--9e0195b4-5053-5472-aeb5-58e98953d00f

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-11

...
...

Threat actors exploited DigiCert’s customer support chat to deliver a malicious ZIP (with a screensaver payload), abused privileged support tooling to obtain initialization codes for pending EV code-signing certificates, and caused the issuance/control of dozens of certificates (60 revoked as a precaution). A subsequent Microsoft Defender security intelligence update mistakenly flagged legitimate DigiCert certificates as Trojan:Win32/Cerdigent.A!dha, triggering widespread quarantines and removal of certificates that disrupted HTTPS, code-signing, and related services; the incident highlights social-engineering of support channels, EDR misconfigurations, and the high impact of PKI/supply-chain compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.