A Microsoft Defender signature update released on April 30 caused legitimate DigiCert root certificates to be identified as malicious, triggering alerts and, in some cases, removing trusted certificates directly from Windows systems. The false positive, tied to a detection named Trojan:Win32/Cerdigent.A!dha, disrupted trust relationships across affected environments and forced IT teams to determine whether they were facing a genuine compromise or an artifact of a broken detection rule.