Whoops: Global Disruption After Microsoft Defender Labels DigiCert as Malware

Tiny CSI figures conduct an investigation on a CPU, blending technology with creativity.

Security tools are designed to answer a simple question: is this safe?

For a brief period in May 2026, Microsoft Defender gave the wrong answer.

Across organisations worldwide, legitimate DigiCert root certificates, the foundation of secure web communication, were flagged as malware. In some cases, they were removed entirely from systems.

What followed was not a breach, but something more disruptive.

What Actually Happened

The issue began with a Microsoft Defender security intelligence update released at the end of April.

Shortly after, systems started reporting detections for Trojan:Win32/Cerdigent.A!dha. The detected files were not malicious software. They were legitimate DigiCert root certificates, widely used to validate secure connections and software signatures.

These certificates sit at the top of the TLS trust chain, forming the basis of how browsers, applications and operating systems verify identity and establish encrypted communication.

Defender responded in line with its configuration. It quarantined or removed the flagged items. In practical terms, that meant deleting entries from the Windows trust store, specifically within the AuthRoot certificate registry.

Once those certificates were removed, systems began to lose the ability to verify trusted connections. Secure websites, signed applications and internal services could no longer be validated with confidence.

Why This Matters

False positives are not unusual in security tooling. What made this incident stand out was the nature of what was flagged and the level of response triggered.

The detection classified the certificates as a high-risk trojan, which led to immediate and often automated remediation. Root certificates are not standard files. They underpin the entire model of digital trust.

Removing them disrupts:

  • validation of HTTPS connections
  • verification of signed executables
  • authentication flows between internal services

At that point, the system continues to function, but the mechanisms used to establish trust are compromised.

What We Think (Likely) Caused It

The incident appears to have been triggered by an error in Defender’s detection logic.

Modern endpoint protection platforms rely on a combination of:

  • signature-based detection
  • behavioural analysis
  • cloud-delivered intelligence

In this case, updated detection logic associated with the “Cerdigent” threat family incorrectly matched legitimate certificate artefacts.

There is an additional layer of context. DigiCert had recently dealt with compromised certificates that required revocation. Detection rules aimed at identifying those compromised elements may have extended too far.

Instead of isolating specific certificates, the detection logic captured objects higher up the trust hierarchy, including trusted root authorities.

This reflects a classic case of over-broad pattern matching, where defensive rules identify shared characteristics between malicious and legitimate objects and apply remediation too widely.

The Operational Impact

Security teams were met with a sudden spike in high-severity alerts. Systems began reporting malware detections tied to critical trust infrastructure. In environments configured with automated response, remediation actions triggered immediately.

The challenge was interpretive as much as technical.

Teams needed to determine whether they were dealing with a genuine compromise or a faulty detection. Acting aggressively risked further disruption. Delaying action introduced uncertainty.

In some reported cases, administrators escalated to full system rebuilds to restore confidence in integrity.

The time required to investigate, validate and repair systems quickly became significant, particularly across larger estates.

Resolution and Recovery

Microsoft addressed the issue by updating its security intelligence definitions. The corrected version removed the false detection and, where possible, restored affected certificates automatically.

The fix was delivered through an updated security intelligence version, which replaced the faulty detection logic.

Recovery still required validation. Trust stores needed to be checked. Certificates needed to be confirmed as present and valid. Systems required monitoring to ensure normal behaviour had resumed.

Restoring trust in the environment took longer than applying the fix itself.

A Broader Pattern

Security tooling is becoming increasingly automated, integrated and dependent on real-time intelligence updates.

That increases detection speed and improves response capability. It also increases the potential impact of errors.

A single faulty update can propagate across thousands of systems in a short period of time. The more centralised the control plane, the wider the effect when something behaves unexpectedly.

This incident demonstrates how quickly that propagation can occur.

A Dr Logic Perspective

The DigiCert false positive highlights a less obvious risk in modern security environments.

Not every incident originates from an external threat. Some come from within the systems designed to provide protection.

Security platforms require oversight. Updates need visibility. Systems need to be resilient enough to recover cleanly when something behaves outside expected parameters.

Confidence in security tooling depends on more than detection accuracy. It depends on control, transparency and the ability to respond effectively when behaviour deviates.

If your organisation is relying on automated security platforms, the priority is maintaining that control across the environment.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.