#1 out of 196.26%
technology3h ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
- Microsoft Defender flagged DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha after a signature update on April 30.
- Administrators reported DigiCert root certificates flagged in the AuthRoot store after the update.
- Microsoft fixed the detections in Security Intelligence update versions 1.449.430.0 and 1.449.431.0.
- DigiCert says the incident involved a breach that allowed access to initialization codes for limited EV code-signing orders.
- DigiCert revoked 60 code-signing certificates in response to the incident.
- The false positives raised concerns among Windows users about device security and potential OS reinstallations.
- DigiCert reported the breach affected a customer support team member and a compromised process in April.
- DigiCert revoked affected EV code-signing certificates after the incident.
- Researchers noted that some DigiCert EV certificates were used in malware campaigns prior to the breach.
- Experts cautioned that Defender detections targeted root certificates, not the revoked code-signing certificates.
Vote 0
