logo

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

ID: 03eb0542-b026-5743-aaba-9064c785799c

STIX ID: report--03eb0542-b026-5743-aaba-9064c785799c

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: Lawrence Abrams

...
...

Microsoft Defender incorrectly detected and in some cases removed DigiCert root certificates from the Windows trust store as Trojan:Win32/Cerdigent.A!dha; Microsoft released a Security Intelligence update (1.449.430.0 → 1.449.431.0) that reportedly fixed the false positives and restored removed certificates. The report also covers a DigiCert security incident in which attackers obtained initialization codes allowing issuance of EV code-signing certificates that were later used to sign malware (associated with the "Zhong Stealer" campaign), DigiCert's revocation of affected certificates, and researcher observations linking newly issued DigiCert EV certs to active malware campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.