Daily brief at 7am Melbourne. Unsubscribe any time.

Monday 4 May 2026

When Your Antivirus Breaks Your Certificates: Microsoft Defender's DigiCert False Positive

Microsoft Defender's false-positive storm is quarantining legitimate DigiCert certificates across Windows fleets — and the US military just signed seven AI companies onto classified systems.

Lead story

When Your Antivirus Breaks Your Certificates: Microsoft Defender's DigiCert False Positive

Security tools are supposed to make your environment safer. When one of the most widely deployed endpoint products on the planet starts flagging legitimate root certificates as malware — and in some cases deleting them — defenders have a very different kind of problem on their hands.

That's exactly what happened over the weekend. Microsoft Defender began detecting valid DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, triggering widespread alerts across Windows fleets globally. In the more serious cases, Defender didn't just alert — it quarantined or removed the certificates entirely. For organisations that rely on DigiCert for TLS, code signing, or internal PKI, that's not a nuisance. It's a potential outage.

What went wrong?

This is a classic false-positive scenario, almost certainly introduced by a signature update that pattern-matched something in the DigiCert certificate structure as suspicious. Antivirus vendors ship signature updates constantly — hundreds per day — and occasionally one goes sideways. The unusual wrinkle here is that it's root certificates being flagged, not executables. Root certs sit at the foundation of trust chains; removing one can silently break certificate validation across a huge range of applications, services, and websites without producing an obvious error message.

Imagine your browser suddenly refusing to load half the internet and not knowing why. That's the downstream effect when a root cert goes missing.

Why it matters beyond the immediate fix

Microsoft has acknowledged the issue and a corrected signature update is the expected resolution path — but the incident illustrates a structural tension in endpoint security that rarely gets discussed. Defender's market share on Windows is enormous. When it makes a mistake at scale, that mistake propagates simultaneously across millions of devices. There's no diversity to absorb the shock.

This is also a reminder that security tooling sits in a privileged position. Defender runs with elevated rights, and a signature error can modify your trust store as confidently as any intended action. It's trust all the way down.

For Australian defenders specifically, DigiCert is one of the dominant certificate authorities used by Australian enterprises, government agencies, and cloud-hosted services. Organisations running Defender in active remediation mode — rather than audit mode — are most exposed. If you've seen unexplained TLS errors or certificate validation failures in your environment this morning, this is your first place to look.

What to watch

Microsoft typically resolves false-positive incidents within hours through an updated intelligence release. The immediate action is to check your Defender security intelligence version and watch for Microsoft's official remediation guidance. If certificates have already been quarantined, restoring them from the Defender quarantine interface is generally straightforward — but validating your trust store afterwards is worth doing carefully.

The broader lesson hasn't changed: security tools need to be treated as a single point of failure risk, not an assumed backstop. Running Defender in audit-only mode in critical environments, or staggering signature update rollouts, are mitigations that never look necessary until exactly this kind of morning.

Also today

US Military Signs Seven AI Giants onto Classified Systems

The US Department of Defense has formalised agreements with seven major technology companies — Google, Microsoft, Amazon Web Services, Nvidia, OpenAI, Reflection, and SpaceX — to deploy their AI capabilities on classified military infrastructure. The Pentagon says the goal is to augment warfighter decision-making in complex operational environments. The deals represent a significant step-change in how commercial AI models will interact with sensitive government data, raising both capability and governance questions. For Australia, which operates under the AUKUS partnership and routinely shares classified infrastructure with US defence systems, the standards these companies apply to classified deployments will have direct downstream relevance.

SecurityWeek

Telegram Mini Apps Are Running a Massive Crypto Scam and Malware Operation

Security researchers have exposed a large-scale fraud network operating through Telegram's Mini App feature — the lightweight in-app tools that let developers build mini services inside Telegram itself. The operation impersonates well-known brands, runs crypto investment scams, and delivers Android malware to victims who engage with the fake apps. Mini Apps are increasingly popular precisely because they feel trustworthy — they sit inside a familiar interface — which makes them an effective social engineering vector. With Telegram's user base substantial across Southeast Asia and Australia, this campaign warrants attention from anyone who uses the platform for community or investment discussions.

Bleeping Computer

"Sorry" Ransomware Is Mass-Exploiting a New cPanel Flaw

A freshly disclosed cPanel vulnerability — CVE-2026-41940 — is already being weaponised at scale by a ransomware group calling its campaign "Sorry." Attackers are using the flaw to breach websites hosted on cPanel and encrypt their data, in what appears to be an opportunistic mass-exploitation run rather than targeted attacks. This is a distinct vulnerability from the authentication bypass covered in Friday's brief, though the speed of exploitation follows the same pattern: cPanel's ubiquity in shared web hosting makes any critical flaw a high-value target within days of disclosure. Australian web hosting providers running cPanel — and there are many — should treat this as an urgent patching priority.

Bleeping Computer

CISA Adds Linux Local Privilege Escalation Flaw to Known Exploited List

CISA has added CVE-2026-31431 — a local privilege escalation vulnerability affecting multiple Linux distributions — to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. With a CVSS score of 7.8, the flaw allows an attacker who already has limited access to a Linux system to escalate to root. LPE vulnerabilities are a staple of multi-stage attacks: they're rarely the initial access vector, but they're frequently the step that turns a foothold into full system compromise. Given Linux's prevalence in Australian cloud and critical infrastructure environments, operators should verify patching status across their distributions immediately.

The Hacker News

Harvard Study: AI Outperformed ER Doctors on Diagnostic Accuracy

A new Harvard study has found that at least one large language model outperformed two emergency room physicians on diagnostic accuracy across a range of real ER cases. Researchers tested multiple LLMs against genuine emergency room presentations and found meaningful accuracy gaps, with AI models — particularly when given full case notes — performing consistently better on complex differential diagnoses. The findings don't suggest AI should replace doctors, but they do strengthen the case for AI as a clinical decision-support tool in under-resourced emergency settings. For Australia's stretched hospital system, where rural and regional EDs often operate with limited specialist support, the implications are worth taking seriously.

TechCrunch

Oscars Rule Out AI-Generated Performances and Scripts

The Academy of Motion Picture Arts and Sciences has updated its eligibility rules to explicitly exclude films with AI-generated actors or AI-written scripts from Oscar consideration. The rule change follows months of industry debate and comes in the wake of several high-profile AI-generated film projects, including work featuring digital actors. The decision effectively draws a hard line between "tool-assisted" filmmaking and AI-generated content — though where exactly that line sits in practice will be contested for years. The move signals that the Academy is siding with the writers' and actors' unions that fought hard over AI provisions during the 2023 SAG-AFTRA strikes.

TechCrunch

'This Is Fine' Creator Says AI Startup Used His Art Without Permission

K.C. Green, the cartoonist behind the iconic "This is fine" dog-in-a-burning-room meme, has publicly accused Artisan — an AI startup perhaps best known for its "stop hiring humans" billboard campaign — of using his artwork in promotional material without consent or compensation. The accusation adds another data point to the ongoing conflict between generative AI companies and artists over unauthorised use of creative work. The irony of Artisan, a company selling AI-powered labour replacement tools, allegedly taking a human artist's work without paying for it, is not subtle. AI copyright cases are slowly making their way through courts in the US and UK; Australia's Copyright Act is increasingly relevant as similar fact patterns emerge locally.

TechCrunch

AI Music Is Flooding Streaming Services — and Nobody Asked For It

A detailed analysis of AI-generated music on major streaming platforms paints a messy picture: AI tracks are being uploaded at enormous volume, often designed to game streaming royalty algorithms rather than attract genuine listeners. The piece traces AI music from early experimental albums in 2018-19 through to today's industrial-scale generation, where some distributors are processing thousands of AI tracks a day. The core tension is economic — streaming royalties are finite, and every AI track that accumulates plays takes revenue from human artists. Spotify and Apple Music have both introduced some safeguards, but enforcement remains porous and the financial incentives for flooding the catalogues haven't gone away.

The Verge

Farewell, Jeeves: Ask.com Closes After 30 Years

IAC has confirmed it is shutting down Ask.com, ending one of the early internet's most recognisable search brands. At its peak in the early 2000s, Ask Jeeves — with its butler mascot — was a genuine competitor to Google, handling hundreds of millions of queries. The site had been operating in a much-reduced capacity for years, largely as a content farm rather than a true search engine. The closure is a quiet footnote in internet history, but it does mark the end of an era when search felt like a contested market. Today, of course, the contest is over AI-powered search — and ironically, Ask.com never managed to pivot credibly to that wave.

TechCrunch

How Do You Issue a Ticket to a Robotaxi?

A sharp piece from TechCrunch Mobility digs into the increasingly practical — and genuinely unresolved — question of traffic enforcement for autonomous vehicles. When a robotaxi runs a red light or parks illegally, who gets the ticket? The vehicle owner? The fleet operator? The software company? Across the US cities where robotaxis are operating, municipalities are discovering their traffic codes were written for humans with licences and addresses. Some jurisdictions are improvising with fines to fleet operators; others are simply not enforcing. As Australia explores AV trials in several states, the regulatory gap identified here is one local transport authorities will need to address before deployment scales.

TechCrunch

Reggie Fils-Aimé: Amazon Once Asked Nintendo to Break the Law

In a guest lecture at NYU, former Nintendo of America president Reggie Fils-Aimé revealed that Nintendo stopped selling its products through Amazon in the DS era because Amazon was requesting preferential pricing arrangements that would have disadvantaged other retailers and potentially violated US competition law. Nintendo held the line, pulled its products, and the two companies eventually reconciled — you can now buy a Switch 2 on Amazon. The anecdote is a rare window into the leverage dynamics between platform owners and big retail, and a reminder that even dominant marketplaces sometimes push too hard. It also lands in a week when antitrust scrutiny of large technology platforms is unusually high.

The Verge

Sources consulted