Microsoft Defender Misclassifies DigiCert Root Certificates as Malware

1 min read
Source: CyberSecurityNews
Microsoft Defender Misclassifies DigiCert Root Certificates as Malware
Photo: CyberSecurityNews
TL;DR Summary

Microsoft Defender’s late-April 2026 signature update wrongly flagged two DigiCert root certificates as malware (Trojan:Win32/Cerdigent.A!dha), quarantining their entries in Windows’ AuthRoot/Certificates store and risking SSL/TLS validation and code-signing for enterprise software. A corrective definition update (.430) began restoring the certificates, with automatic remediation rolling out and admins advised to verify restoration via certutil and Advanced Hunting logs. This incident underscores the risks of false positives in automated security responses targeting core Windows components.

Share this article

Reading Insights

Total Reads

0

Unique Readers

18

Time Saved

58 min

vs 59 min read

Condensed

99%

11,61573 words

Want the full story? Read the original article

Read on CyberSecurityNews