A faulty Microsoft Defender signature update released on April 30 incorrectly detected legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, triggering alerts across Windows environments and, in some cases, quarantining or removing trusted roots from stores such as AuthRoot. The flagged thumbprints were tied to valid DigiCert trust anchors, including DigiCert Assured ID Root CA and DigiCert Trusted Root G4, causing administrators and SOC teams to suspect compromise and disrupting certificate trust relationships used for TLS validation and code signing.
Microsoft later acknowledged the detections were erroneous and remediated the issue with updated Defender security intelligence, including version 1.449.430.0 or later. Reporting indicates the overly broad detection logic may have stemmed from Microsoft’s response to a separate DigiCert code-signing certificate incident linked to abuse such as the Zhong Stealer campaign, but the certificates flagged in this case were legitimate and not revoked. The false positive prompted some organizations to take unnecessary recovery actions, including system rebuilds, underscoring the operational risk of automated detections that affect root certificate trust stores.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft later corrected the erroneous detection logic and advised use of Security Intelligence version 1.449.430.0 or later. The update stopped legitimate DigiCert root certificates from being misidentified as malware.
On 2026-05-03, Windows administrators and SOC analysts began reporting repeated Defender detections for Trojan:Win32/Cerdigent.A!dha affecting legitimate DigiCert root certificates. On some systems, Defender quarantined or removed trusted certificates from stores such as AuthRoot, disrupting trust relationships and prompting incident response actions.
A Microsoft Defender security intelligence update released on 2026-04-30 introduced detection logic that incorrectly flagged legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha. The faulty logic was reportedly tied to Microsoft's response to a DigiCert-related code-signing certificate security incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcecensys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.