CoolCatGee
14.3K posts








Anyone else seeing Microsoft #Defender flagging #DigiCert root certificate registry keys as malware? We’ve seen reports that Defender signature update from April 30 added a detection called: Trojan:Win32/Cerdigent.A!dha In some environments, Defender apparently detected DigiCert Root CA certificate registry entries and removed them from the trust store. The affected cert hashes mentioned so far: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 Example path: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 There’s also a Reddit comment suggesting Microsoft has started restoring the certs and that admins can check this via Advanced Hunting in Defender: DeviceRegistryEvents | where RegistryKey contains "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" or RegistryKey contains "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4" | where ActionType == "RegistryKeyCreated" | where Timestamp > datetime(2026-05-03T04:00:00) | project Timestamp, DeviceName, ActionType, InitiatingProcessFileName | order by Timestamp desc On an affected device, this can also be checked with: certutil -store AuthRoot | findstr -i "digicert" Could become an annoying day for admins if this spreads reddit.com/r/cybersecurit…




🧵🚨 BREAKING: Miles Taylor: "Anonymous," former DHS Chief of Staff, Google security executive launched a website called GTFO ICE that collects your full name, email, phone number, and zip code to join an anti-ICE "rapid response network." And publishes the user infromation via a public API. 🚨 17,662 people have signed up. The sign-up data is exposed on a public REST API. No true authentication. No rate limiting. Full records: names, emails, phone numbers, zip codes, timestamps. The man who ran the third-largest federal department (250,000 employees, $60 billion budget) who oversaw election security architecture and led counterterrorism operations, then served as Google's Head of National Security Policy... ...can't secure a sign-up form. But he does milk hundreds of thousands of NGO dollars on these credentials. While freeloading off his fame as the person who wrote the infamous NYT article "I Am Part of the Resistance Inside the Trump Administration." And despite me pinging @MilesTaylorUSA about this 12 hours ago, the REST API is still wide open and exposed as of now. Everything has been turned over to FBI, HSI, ICE, and more agencies. As always, patience as I pull together the thread. 👇




















