Bg Shape
Image

Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

1. Miasma Worm Hits 73 Microsoft GitHub Repositories

What happened

The Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026, using a previously stolen contributor account to push a malicious commit to the Azure/durabletask repository. The commit planted configuration files that triggered a credential-harvesting payload automatically when a developer opened the repository in VS Code, Claude Code, Cursor, or Gemini CLI. No clicking, no additional action required. Simply opening the repository was enough to trigger the worm, which then exfiltrated developer credentials and cloud certificates including AWS, Azure, and GCP keys. GitHub disabled all 73 repositories within 105 seconds of detection.

What to do

  • Any developer who cloned or opened an affected Microsoft repository between June 3 and June 5, 2026 should treat all credentials on their machine as compromised and rotate immediately
  • This includes GitHub tokens, AWS keys, Azure service principals, GCP service accounts, Kubernetes secrets, and SSH keys
  • Audit CI/CD pipelines for any secrets that may have been accessed from affected machines

2. Microsoft's Largest Ever Patch Tuesday: 200 Vulnerabilities, Secure Boot Deadline

What happened

Microsoft's June 2026 Patch Tuesday addressed 200 vulnerabilities, including 33 rated Critical and six zero-days. Several of the flaws were discovered with AI assistance and had already been exploited, including the YellowKey vulnerability (CVE-2026-45585), a BitLocker bypass that allowed attackers with physical access to gain unrestricted access to encrypted drives via the Windows Recovery Environment.

Critically, this is the last Patch Tuesday before the Secure Boot certificates issued in 2011 expire on June 26, 2026. Devices that are not patched in time will continue to operate but will lose all future early-boot security protections. Organisations using virtual machines and VDIs are particularly exposed if patches are not applied before that date.

What to do

  • Apply June Patch Tuesday updates this week without delay
  • Prioritise VM and VDI environments given the Secure Boot certificate expiry
  • Verify Secure Boot status in Windows Security settings after patching

3. Confirmed Microsoft Defender Bypass: Patch Now When Available

What happened

A security researcher has published a confirmed bypass of Microsoft Defender, tracked as CVE-2026-50656 and known as RoguePlanet. The flaw is a race condition in the Microsoft Malware Protection Engine that allows an attacker who already has a foothold on a machine to escalate privileges to SYSTEM level, effectively giving full control over the device. The exploit works on fully patched Windows 10 and Windows 11 systems, including those with the June Patch Tuesday updates applied. It is not yet confirmed whether this was an existing bug or one introduced in the June patch cycle.

Microsoft has rated it "Exploitation More Likely" and an out-of-band patch has since been released via Microsoft Malware Protection Engine version 1.1.26060.3008, delivered through Defender auto-update.

What to do

  • Confirm Defender has updated to Malware Protection Engine version 1.1.26060.3008 or later
  • Monitor endpoints for unexpected SYSTEM-level processes or privilege escalation activity
  • Keep a close eye on the Microsoft security portal for further out-of-band updates

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Read Our Latest Blogs

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Blog Image
Ghost Executive: The Fast-Growing Fraud Impersonating Your Leadership

A Ghost Executive attack is a form of business email compromise (BEC) in which a fraudster impersonates a senior figure to authorise a fraudulent payment or reroute a legitimate one. Read more at Smarttech247

Blog Image
Autonomous AI Attacks, Ransomware Disruption, and a Critical WordPress Threat

Explore this week's Risk Radar covering autonomous AI cyberattacks, the Anubis ransomware attack, and a critical WordPress vulnerability, with key guidance for CISOs.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

Vulnerabilities and Exposure
Cloud and Infrastructure
Threat Actors and Campaigns
Robert Kehoe
Chief Technology Officer
June 13, 2026

1. Miasma Worm Hits 73 Microsoft GitHub Repositories

What happened

The Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026, using a previously stolen contributor account to push a malicious commit to the Azure/durabletask repository. The commit planted configuration files that triggered a credential-harvesting payload automatically when a developer opened the repository in VS Code, Claude Code, Cursor, or Gemini CLI. No clicking, no additional action required. Simply opening the repository was enough to trigger the worm, which then exfiltrated developer credentials and cloud certificates including AWS, Azure, and GCP keys. GitHub disabled all 73 repositories within 105 seconds of detection.

What to do

  • Any developer who cloned or opened an affected Microsoft repository between June 3 and June 5, 2026 should treat all credentials on their machine as compromised and rotate immediately
  • This includes GitHub tokens, AWS keys, Azure service principals, GCP service accounts, Kubernetes secrets, and SSH keys
  • Audit CI/CD pipelines for any secrets that may have been accessed from affected machines

2. Microsoft's Largest Ever Patch Tuesday: 200 Vulnerabilities, Secure Boot Deadline

What happened

Microsoft's June 2026 Patch Tuesday addressed 200 vulnerabilities, including 33 rated Critical and six zero-days. Several of the flaws were discovered with AI assistance and had already been exploited, including the YellowKey vulnerability (CVE-2026-45585), a BitLocker bypass that allowed attackers with physical access to gain unrestricted access to encrypted drives via the Windows Recovery Environment.

Critically, this is the last Patch Tuesday before the Secure Boot certificates issued in 2011 expire on June 26, 2026. Devices that are not patched in time will continue to operate but will lose all future early-boot security protections. Organisations using virtual machines and VDIs are particularly exposed if patches are not applied before that date.

What to do

  • Apply June Patch Tuesday updates this week without delay
  • Prioritise VM and VDI environments given the Secure Boot certificate expiry
  • Verify Secure Boot status in Windows Security settings after patching

3. Confirmed Microsoft Defender Bypass: Patch Now When Available

What happened

A security researcher has published a confirmed bypass of Microsoft Defender, tracked as CVE-2026-50656 and known as RoguePlanet. The flaw is a race condition in the Microsoft Malware Protection Engine that allows an attacker who already has a foothold on a machine to escalate privileges to SYSTEM level, effectively giving full control over the device. The exploit works on fully patched Windows 10 and Windows 11 systems, including those with the June Patch Tuesday updates applied. It is not yet confirmed whether this was an existing bug or one introduced in the June patch cycle.

Microsoft has rated it "Exploitation More Likely" and an out-of-band patch has since been released via Microsoft Malware Protection Engine version 1.1.26060.3008, delivered through Defender auto-update.

What to do

  • Confirm Defender has updated to Malware Protection Engine version 1.1.26060.3008 or later
  • Monitor endpoints for unexpected SYSTEM-level processes or privilege escalation activity
  • Keep a close eye on the Microsoft security portal for further out-of-band updates

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365