Bg Shape
Image

Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

1. Miasma Worm Hits 73 Microsoft GitHub Repositories

What happened

The Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026, using a previously stolen contributor account to push a malicious commit to the Azure/durabletask repository. The commit planted configuration files that triggered a credential-harvesting payload automatically when a developer opened the repository in VS Code, Claude Code, Cursor, or Gemini CLI. No clicking, no additional action required. Simply opening the repository was enough to trigger the worm, which then exfiltrated developer credentials and cloud certificates including AWS, Azure, and GCP keys. GitHub disabled all 73 repositories within 105 seconds of detection.

What to do

  • Any developer who cloned or opened an affected Microsoft repository between June 3 and June 5, 2026 should treat all credentials on their machine as compromised and rotate immediately
  • This includes GitHub tokens, AWS keys, Azure service principals, GCP service accounts, Kubernetes secrets, and SSH keys
  • Audit CI/CD pipelines for any secrets that may have been accessed from affected machines

2. Microsoft's Largest Ever Patch Tuesday: 200 Vulnerabilities, Secure Boot Deadline

What happened

Microsoft's June 2026 Patch Tuesday addressed 200 vulnerabilities, including 33 rated Critical and six zero-days. Several of the flaws were discovered with AI assistance and had already been exploited, including the YellowKey vulnerability (CVE-2026-45585), a BitLocker bypass that allowed attackers with physical access to gain unrestricted access to encrypted drives via the Windows Recovery Environment.

Critically, this is the last Patch Tuesday before the Secure Boot certificates issued in 2011 expire on June 26, 2026. Devices that are not patched in time will continue to operate but will lose all future early-boot security protections. Organisations using virtual machines and VDIs are particularly exposed if patches are not applied before that date.

What to do

  • Apply June Patch Tuesday updates this week without delay
  • Prioritise VM and VDI environments given the Secure Boot certificate expiry
  • Verify Secure Boot status in Windows Security settings after patching

3. Confirmed Microsoft Defender Bypass: Patch Now When Available

What happened

A security researcher has published a confirmed bypass of Microsoft Defender, tracked as CVE-2026-50656 and known as RoguePlanet. The flaw is a race condition in the Microsoft Malware Protection Engine that allows an attacker who already has a foothold on a machine to escalate privileges to SYSTEM level, effectively giving full control over the device. The exploit works on fully patched Windows 10 and Windows 11 systems, including those with the June Patch Tuesday updates applied. It is not yet confirmed whether this was an existing bug or one introduced in the June patch cycle.

Microsoft has rated it "Exploitation More Likely" and an out-of-band patch has since been released via Microsoft Malware Protection Engine version 1.1.26060.3008, delivered through Defender auto-update.

What to do

  • Confirm Defender has updated to Malware Protection Engine version 1.1.26060.3008 or later
  • Monitor endpoints for unexpected SYSTEM-level processes or privilege escalation activity
  • Keep a close eye on the Microsoft security portal for further out-of-band updates

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Read Our Latest Blogs

Blog Image
Three Things Security Leaders Must Know About NIS 2

Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.

Blog Image
Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

This week's Risk Radar covers the Miasma supply chain worm hitting 73 Microsoft GitHub repositories, the largest Patch Tuesday in Microsoft's history including a critical Secure Boot deadline, and a confirmed Microsoft Defender bypass that lets attackers elevate to SYSTEM privileges.

Blog Image
Why your NIS2 Gap Might Sit Outside IT

Discover why NIS2 readiness needs to move beyond policy documents and into operational response planning across IT, OT, and supplier ecosystems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

Vulnerabilities and Exposure
Cloud and Infrastructure
Threat Actors and Campaigns
Robert Kehoe
Chief Technology Officer
June 13, 2026

1. Miasma Worm Hits 73 Microsoft GitHub Repositories

What happened

The Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026, using a previously stolen contributor account to push a malicious commit to the Azure/durabletask repository. The commit planted configuration files that triggered a credential-harvesting payload automatically when a developer opened the repository in VS Code, Claude Code, Cursor, or Gemini CLI. No clicking, no additional action required. Simply opening the repository was enough to trigger the worm, which then exfiltrated developer credentials and cloud certificates including AWS, Azure, and GCP keys. GitHub disabled all 73 repositories within 105 seconds of detection.

What to do

  • Any developer who cloned or opened an affected Microsoft repository between June 3 and June 5, 2026 should treat all credentials on their machine as compromised and rotate immediately
  • This includes GitHub tokens, AWS keys, Azure service principals, GCP service accounts, Kubernetes secrets, and SSH keys
  • Audit CI/CD pipelines for any secrets that may have been accessed from affected machines

2. Microsoft's Largest Ever Patch Tuesday: 200 Vulnerabilities, Secure Boot Deadline

What happened

Microsoft's June 2026 Patch Tuesday addressed 200 vulnerabilities, including 33 rated Critical and six zero-days. Several of the flaws were discovered with AI assistance and had already been exploited, including the YellowKey vulnerability (CVE-2026-45585), a BitLocker bypass that allowed attackers with physical access to gain unrestricted access to encrypted drives via the Windows Recovery Environment.

Critically, this is the last Patch Tuesday before the Secure Boot certificates issued in 2011 expire on June 26, 2026. Devices that are not patched in time will continue to operate but will lose all future early-boot security protections. Organisations using virtual machines and VDIs are particularly exposed if patches are not applied before that date.

What to do

  • Apply June Patch Tuesday updates this week without delay
  • Prioritise VM and VDI environments given the Secure Boot certificate expiry
  • Verify Secure Boot status in Windows Security settings after patching

3. Confirmed Microsoft Defender Bypass: Patch Now When Available

What happened

A security researcher has published a confirmed bypass of Microsoft Defender, tracked as CVE-2026-50656 and known as RoguePlanet. The flaw is a race condition in the Microsoft Malware Protection Engine that allows an attacker who already has a foothold on a machine to escalate privileges to SYSTEM level, effectively giving full control over the device. The exploit works on fully patched Windows 10 and Windows 11 systems, including those with the June Patch Tuesday updates applied. It is not yet confirmed whether this was an existing bug or one introduced in the June patch cycle.

Microsoft has rated it "Exploitation More Likely" and an out-of-band patch has since been released via Microsoft Malware Protection Engine version 1.1.26060.3008, delivered through Defender auto-update.

What to do

  • Confirm Defender has updated to Malware Protection Engine version 1.1.26060.3008 or later
  • Monitor endpoints for unexpected SYSTEM-level processes or privilege escalation activity
  • Keep a close eye on the Microsoft security portal for further out-of-band updates

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365