Microsoft Defender flags DigiCert root certificates as malware, triggering trust disruptions

TL;DR Summary
Microsoft Defender's late-April signature update falsely flagged DigiCert root certificates as malware, causing removals from the Windows trust store and disruptions to secure connections; Microsoft issued emergency Defender definitions (1.449.430.0 and 1.449.431.0) to fix the issue and auto-restore certificates. While timing touches a DigiCert breach incident, Defender targeted root certificates, not EV signing certs, underscoring the risk of false positives in automated threat detection and the need for layered security.
Topics:technology#certificates#digicert#false-positives#microsoft-defender#security#windows-trust-store
- Microsoft Defender Misidentifies DigiCert Certificates As Malware, Triggering Global Disruptions LinkedIn
- Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware CyberSecurityNews
- Microsoft Defender flagging "Cerdigent" trojan malware on Windows 11, Server PCs worldwide Neowin
- DigiCert breached via malicious screensaver file Help Net Security
- Windows “Cerdigent” Threat Warnings Spread, But Many May Be False Positives Windows Report
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
4 min
vs 5 min read
Condensed
93%
935 → 70 words
Want the full story? Read the original article
Read on LinkedIn