Microsoft Defender DigiCert Certificate False Positive Detection | MSSP Advisory
High
DateMay 5, 2026
📋Executive Summary
Microsoft Defender flagged legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha malware through false positive detections based on SHA-1 hash identification. The false alerts targeted specific DigiCert root certificates that are widely deployed across enterprise environments. Microsoft has acknowledged the issue and pushed signature updates to resolve the false positive detections.
⚠️Why It Matters for MSSPs
Your RMM agents and endpoint management tools running Defender are generating critical malware alerts on legitimate certificates, creating noise that masks real threats and triggering unnecessary client panic calls. Clients are seeing certificate-based security warnings across their infrastructure, and they expect you to distinguish between false positives and actual certificate compromise attacks.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.