DigiCert Root Certificates Incorrectly Detected as Malware by Microsoft Defender

On May 3, 2026, system administrators and everyday users worldwide experienced a sudden, massive spike in severe security alerts from Microsoft Defender. The native Windows security platform began aggressively flagging system files as “Trojan:Win32/Cerdigent.A!dha.”

This unexpected detection caused widespread panic across IT departments, leading many professionals to believe a sophisticated threat actor had actively compromised their enterprise networks.

The anxiety intensified rapidly because standard remediation efforts proved completely ineffective.

Users reported that quick scans, comprehensive full system sweeps, and even Microsoft Defender’s specialized offline malware detector could not quarantine or clear the stubborn warning.

The persistence of the alert drove some frustrated individuals to completely reset their Windows operating systems, unnecessarily destroying local data in a desperate attempt to eradicate the phantom malware.

EDR Discrepancies and Root Certificate Identification

Suspicions of a massive false positive grew when IT professionals began cross-referencing the Microsoft Defender alerts with alternative security solutions.

Leading third-party endpoint detection and response platforms, including SentinelOne, Arctic Wolf, and Malwarebytes, reported clean scans across the same environments.

This isolated alerting behavior strongly pointed to a flawed threat definition update within Microsoft’s security ecosystem rather than a genuine global malware outbreak.

Technical community researchers quickly zeroed in on the specific files triggering the aggressive Defender alert. Microsoft’s security engine was directly targeting two specific root certificates, identified by the following cryptographic hashes:

  • 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
  • DDFB16CD4931C973A2037D3FC83A4D7D775D05E4

These specific hashes correspond to legitimate DigiCert root certificates. Root certificates are critical infrastructure components used to verify the authenticity of secure web traffic and digitally signed software.

The sudden detection appears closely connected to broader cybersecurity industry actions regarding certificate trust and revocation.

Recent technical discussions, including active Mozilla bug tracker entries, indicate that major browser and operating system vendors are coordinating the removal of specific root certificates that threat actors have recently exploited.

Microsoft’s initial attempt to block these compromised certificates likely resulted in an overly broad, aggressive detection rule that mistakenly caught legitimate DigiCert assets.

Microsoft engineers quickly identified the flawed logic and released a critical patch to correct the detection engine’s behavior.

The false positive issue is officially resolved in the Microsoft Security definition update version 1.449.430.0.

To resolve the persistent Trojan warnings immediately, system administrators must force a manual signature update. Organizations should deploy KB2267602, the definition update, across their endpoints to restore normal operations.

Once the system applies the newest definitions, Microsoft Defender will correctly process the DigiCert root certificates, instantly clearing the alarming alerts without requiring any further system resets or complex incident response procedures.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *