Most security teams spend their days worrying about attackers from the outside. External threat actors, brute-force login attempts, suspicious IP ranges, phishing lures. That’s fair. But this week handed us a sharp reminder that your security stack itself can be a liability. The Microsoft Defender false positive on DigiCert certificates isn’t just a weird bug story. It’s a cybersecurity case study in what happens when the tools you trust to protect you start breaking the infrastructure you rely on.

Microsoft Defender false positive flags DigiCert certificates as malware
Microsoft Defender began flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha. (Source: BleepingComputer)

The DigiCert Defender Mess Is Worse Than a False Positive

Call it what it is: a self-inflicted outage risk. Microsoft Defender started flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, and in some environments, it didn’t just alert. It removed certificates from Windows. Certificate removal isn’t a nuisance alert you dismiss after morning standup. Depending on what those certs anchor, you’re looking at broken SSL/TLS chains, failed code signing validation, application authentication failures, and potentially a lot of confused end users and frantic tickets.

For security engineers, this is the nightmare version of a false positive. The whole value proposition of endpoint protection is that it acts autonomously, at scale, across your fleet. When that autonomy is pointed at foundational PKI infrastructure, the blast radius is wide. And because Defender integrates tightly with Windows itself, the remediation path isn’t as simple as “just disable the rule.” You’re now doing certificate hygiene at scale, on potentially hundreds or thousands of machines, some of which may not have inventory coverage.

What Actually Breaks When Certificates Get Removed

The immediate casualties depend heavily on your environment, but here’s the short version of what’s at risk:

  1. Code signing validation: Unsigned or invalidated executables get blocked by application control policies, which can halt business-critical software silently or with cryptic error messages.
  2. HTTPS trust chains: Internal web services and APIs that chain up to an affected root will throw certificate errors, breaking integrations, dashboards, and monitoring agents.
  3. Authentication and identity: Certificate-based authentication, including smart card logon and some MFA configurations, depends on trusted root stores being intact. Remove the wrong cert and you can lock users out entirely.
  4. Security tooling itself: Many endpoint agents and EDR solutions use TLS for communication back to their management consoles. If the cert chain breaks, your threat detection coverage can go dark quietly while you’re looking elsewhere.

That last point matters most. An attacker who understands your security stack can time exploitation to moments when your visibility is degraded. Operational chaos, whether from a bad update or a false positive cascade, is exactly the kind of window that threat actors historically love to use.

Wireshark 4.6.5 Deserves More Respect Than It’s Getting

SANS Internet Storm Center logo, source for Wireshark 4.6.5 vulnerability coverage
SANS ISC flagged the Wireshark 4.6.5 release, which addresses 38 CVEs and 35 bugs. (Source: SANS ISC)

Wireshark 4.6.5 dropped with fixes for 43 vulnerabilities, 38 of which are tracked as CVEs, along with 35 bug fixes. The security community tends to treat Wireshark updates as routine, and that’s a mistake. Packet analyzers run with elevated privileges. They parse arbitrary, attacker-controlled network data. If your operations team or SOC analysts are running an outdated Wireshark build while doing threat detection or incident response work on a live network, you’ve handed a potential exploit path to anyone who can influence the packets they’re analyzing.

Consider the scenario: an analyst is investigating a suspected C2 channel, capturing and reviewing traffic on a compromised segment. The traffic itself contains a crafted payload targeting a Wireshark dissector vulnerability. The analyst’s machine is now the target. This sounds hypothetical until you remember that security engineers tend to have elevated access, privileged credentials, and connections to management networks. Targeting the analyst through their tools is a solid lateral movement strategy.

Patch Wireshark. Yes, even on air-gapped analyst workstations. Especially on air-gapped analyst workstations, actually, since those often see the least routine maintenance attention.

AI on Classified Military Networks Raises Real Cybersecurity Questions

The Pentagon has signed agreements with Google, Microsoft, Amazon Web Services, Nvidia, OpenAI, Reflection, and SpaceX to deploy AI systems on classified networks for warfighter decision support. On the surface, this reads as a procurement announcement. Dig a little, and there are serious cybersecurity and security hardening implications worth unpacking for anyone who operates sensitive or high-consequence environments.

The core tension is this: AI systems are data-hungry, model-update-dependent, and often require ongoing cloud connectivity to function well. Classified environments are deliberately isolated, tightly controlled, and deeply skeptical of any data egress pathway. Threading that needle without creating new attack surface requires extraordinary care in network architecture, and the track record of technology deployments in classified environments includes some genuinely expensive lessons.

There’s also the threat detection angle. AI inference systems process inputs, generate outputs, and in many configurations, log everything. If an adversary can poison the inputs or influence the training pipeline, the output of the AI becomes a vector for misinformation inside the decision loop. Defense in depth for AI systems in sensitive environments means treating the model itself as a component that needs integrity monitoring, not just the network perimeter around it.

This isn’t an argument against military AI adoption. It’s an argument that cybersecurity architecture for these deployments has to lead, not follow, the capability rollout.

What You Should Actually Do Right Now

These three stories share a common thread: the controls and tools you rely on carry their own risk profiles. Here’s how to tighten your posture based on what this week revealed.

Immediate Actions

For the Defender/DigiCert situation, pull your Defender alerts from the last 48 to 72 hours and filter for Trojan:Win32/Cerdigent.A!dha detections. Cross-reference against your certificate inventory. If any machines show remediation actions taken, audit their trusted root certificate stores manually before pushing any automatic restore. Microsoft is expected to issue a signature update fix, but don’t wait passively; confirm the scope in your environment now.

For Wireshark, check every analyst workstation, SOC jumpbox, and network engineering system in your inventory. If anything is running below 4.6.5, treat it as a patching priority this week, not next sprint. The patch is stable and the vulnerability count is large enough that it should not wait for a monthly patching cycle.

Ongoing Defensive Posture

  • Inventory your certificate trust stores actively. Most organizations can’t tell you in real time which machines have had their trusted root stores modified. If that’s true in your environment, fix it with a monitoring script or endpoint query before the next incident surfaces it for you.
  • Treat security tool updates as a separate patch track. Endpoint agents, packet analyzers, SIEM forwarders, and similar tools often fall outside standard software patching workflows. They deserve their own update cadence and compliance reporting.
  • Build firewall rules and network segmentation that assume tool compromise. Even your security tools should operate with least-privilege network access. An analyst workstation running Wireshark has no reason to have unrestricted egress to your management VLAN.
  • Test your incident response runbooks against false positive scenarios. Most IR playbooks assume attacker activity as the trigger. A Defender update that removes legitimate certificates across your fleet is an operational incident that needs a response plan too.
  • Apply security hardening to AI inference systems the same way you’d harden any privileged service. Input validation, access logging, model integrity checks, and strict egress control are the minimum baseline.

Frequently Asked Questions

How do I check if Defender removed DigiCert certificates from my Windows machines?
Open the Event Viewer on affected endpoints and look for events in the Windows Defender operational log indicating quarantine or removal actions tied to the Cerdigent.A!dha detection. You can also query the certificate store via PowerShell using Get-ChildItem Cert:\LocalMachine\Root and cross-reference against a known-good baseline from a machine that wasn’t affected. If you use an EDR with timeline capability, search for certificate store modification events in the same timeframe as the Defender alert spike.
Is Wireshark really a meaningful attack surface for threat actors?
Yes, and the risk is higher than most teams acknowledge. Wireshark parses dozens of complex network protocols, each with its own dissector code that processes attacker-influenced data. Historically, Wireshark has had exploitable memory corruption bugs in its dissectors. An analyst capturing traffic on a hostile network segment, or processing a packet capture file received from an external party, is directly exposing that attack surface. The key risk multiplier is that security analysts often have more privileged access than average users.
What cybersecurity architecture principles apply when deploying AI on sensitive networks?
The same principles that govern any high-privilege service deployment, plus a few AI-specific ones. Defense in depth means you don’t just protect the network perimeter; you protect the model inputs, the output pipelines, and the update mechanisms. Strict data minimization reduces the value of any compromise. And threat detection for AI systems should include behavioral monitoring of the AI’s outputs for signs of manipulation, not just network-layer monitoring around the system. Treat model updates as you’d treat code deployments: reviewed, signed, and auditable.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.