Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
ID: 03eb0542-b026-5743-aaba-9064c785799c
STIX ID: report--03eb0542-b026-5743-aaba-9064c785799c
Feed Name: Bleeping Computer
Microsoft Defender incorrectly detected and in some cases removed DigiCert root certificates from the Windows trust store as Trojan:Win32/Cerdigent.A!dha; Microsoft released a Security Intelligence update (1.449.430.0 → 1.449.431.0) that reportedly fixed the false positives and restored removed certificates. The report also covers a DigiCert security incident in which attackers obtained initialization codes allowing issuance of EV code-signing certificates that were later used to sign malware (associated with the "Zhong Stealer" campaign), DigiCert's revocation of affected certificates, and researcher observations linking newly issued DigiCert EV certs to active malware campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
