TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

TechRepublic

Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates

Ken Underhill · 2 days ago · Read original ↗

ATT&CK techniques detected

6 predictions
T1195.002Compromise Software Supply Chain
75%
“update released on apr. 30, which introduced detections for trojan : win32 / cerdigent. a! dha. soon after, administrators reported legitimate digicert root certificates being flagged as malicious and removed from the windows trust store. on affected systems, this included deleti…”
T1588.003Code Signing Certificates
70%
“update released on apr. 30, which introduced detections for trojan : win32 / cerdigent. a! dha. soon after, administrators reported legitimate digicert root certificates being flagged as malicious and removed from the windows trust store. on affected systems, this included deleti…”
T1195.002Compromise Software Supply Chain
57%
“microsoft defender bug triggers false malware alerts for digicert certificates image : rawpixel / envato microsoft fixed a defender false positive that flagged legitimate digicert certificates as malware, disrupting windows trust stores for some it teams. written by ken underhill…”
T1195Supply Chain Compromise
32%
“the latest defender update. - uk police convicts pair in £5. 5 billion bitcoin launder case - blackpoint cyber vs. arctic wolf : which mdr solution is right for you? - how github is securing the software supply chain - 8 best enterprise password managers advertisement minimize im…”
T1588.003Code Signing Certificates
32%
“microsoft defender bug triggers false malware alerts for digicert certificates image : rawpixel / envato microsoft fixed a defender false positive that flagged legitimate digicert certificates as malware, disrupting windows trust stores for some it teams. written by ken underhill…”
T1649Steal or Forge Authentication Certificates
32%
“microsoft defender bug triggers false malware alerts for digicert certificates image : rawpixel / envato microsoft fixed a defender false positive that flagged legitimate digicert certificates as malware, disrupting windows trust stores for some it teams. written by ken underhill…”

Summary

Microsoft fixed a Defender false positive that flagged legitimate DigiCert certificates as malware, disrupting Windows trust stores for some IT teams.

The post Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates appeared first on TechRepublic.