Security Snafu: Microsoft Defender Goes Rogue Against Trusted DigiCert Certificates
A recent security update for Microsoft Defender inadvertently caused the software to identify two legitimate DigiCert root certificates as malicious entities. This false positive triggered widespread alerts across enterprise environments, creating significant risks for SSL/TLS validation and code-signing processes. Since these certificates are foundational to establishing secure connections and verifying software authenticity, the error threatened to disrupt encrypted communications and block legitimate applications. Microsoft has acknowledged the issue, which stems from a signature update that incorrectly flagged the certificate authority's infrastructure.