Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


What happened
The Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026, using a previously stolen contributor account to push a malicious commit to the Azure/durabletask repository. The commit planted configuration files that triggered a credential-harvesting payload automatically when a developer opened the repository in VS Code, Claude Code, Cursor, or Gemini CLI. No clicking, no additional action required. Simply opening the repository was enough to trigger the worm, which then exfiltrated developer credentials and cloud certificates including AWS, Azure, and GCP keys. GitHub disabled all 73 repositories within 105 seconds of detection.
What to do
What happened
Microsoft's June 2026 Patch Tuesday addressed 200 vulnerabilities, including 33 rated Critical and six zero-days. Several of the flaws were discovered with AI assistance and had already been exploited, including the YellowKey vulnerability (CVE-2026-45585), a BitLocker bypass that allowed attackers with physical access to gain unrestricted access to encrypted drives via the Windows Recovery Environment.
Critically, this is the last Patch Tuesday before the Secure Boot certificates issued in 2011 expire on June 26, 2026. Devices that are not patched in time will continue to operate but will lose all future early-boot security protections. Organisations using virtual machines and VDIs are particularly exposed if patches are not applied before that date.
What to do
What happened
A security researcher has published a confirmed bypass of Microsoft Defender, tracked as CVE-2026-50656 and known as RoguePlanet. The flaw is a race condition in the Microsoft Malware Protection Engine that allows an attacker who already has a foothold on a machine to escalate privileges to SYSTEM level, effectively giving full control over the device. The exploit works on fully patched Windows 10 and Windows 11 systems, including those with the June Patch Tuesday updates applied. It is not yet confirmed whether this was an existing bug or one introduced in the June patch cycle.
Microsoft has rated it "Exploitation More Likely" and an out-of-band patch has since been released via Microsoft Malware Protection Engine version 1.1.26060.3008, delivered through Defender auto-update.
What to do
Stay safe and share this with your team.
Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.
We protect your on-premise/cloud/OT environments - 24x7x365