decrypted · 10 july 2026 · vulnerabilities and patching
Microsoft Defender's own blind spot, and the researcher who wouldn't stay quiet
Microsoft spent the past month patching a flaw in the very software meant to catch attackers: a race condition in the scanning engine behind Windows Defender that let a local user become SYSTEM in roughly the time it takes the scanner to check its own paperwork. The bug, CVE-2026-50656 and nicknamed RoguePlanet, reached the public not through coordinated disclosure but through a researcher's public feud with the company whose software he was reporting bugs in. Microsoft shipped the fix on 8 July, twenty-nine days after working exploit code went online. For UK organisations running the default antivirus on most of their Windows machines, the interesting part isn't the bug. It's what the bug, and the way it surfaced, say about trusting security software to defend itself.
A scanner racing against itself
RoguePlanet lives in the Microsoft Malware Protection Engine, the component that does the actual file scanning behind Windows Defender. Trigger the race condition at the right moment and it spawns a command prompt running as SYSTEM, the highest privilege level on the machine, regardless of whether real-time protection is switched on. Picture a security guard whose master key can be copied in the half-second it takes him to glance at your badge: the checking mechanism and the thing it protects share the same weak moment.
A researcher going by Nightmare Eclipse published working exploit code on 9 June. Microsoft's own advisory, five days later, rated it CVSS 7.8 and "exploitation more likely". The patch arrived on 8 July as an update to the scanning engine rather than through the normal Patch Tuesday cycle. Microsoft says it has not confirmed RoguePlanet itself being used in real attacks, though three of Nightmare Eclipse's earlier Windows disclosures have since turned up in the wild, which makes that "not yet" feel provisional rather than reassuring.
A dispute over disclosure
Nightmare Eclipse, who claims to be a former Microsoft employee, has published seven Windows zero-days since March amid an increasingly public row with Microsoft over how it handles vulnerability reports, alleging ignored submissions and deleted researcher accounts. Microsoft initially warned that publishing exploit code could carry legal consequences, then walked that back after criticism from the security community. The researcher says Microsoft also had proof-of-concept repositories pulled from GitHub and GitLab.
Two lessons sit inside this story. First, anything with SYSTEM-level reach because it must touch every file on a machine is, by design, a higher-value target than the applications it protects, and deserves scrutiny and monitoring to match, not the install-and-forget treatment antivirus usually gets. Second, a vendor that treats independent researchers as adversaries turns bugs that could have been fixed quietly into bugs fixed in public, on the researcher's timeline rather than the defender's. UK organisations should be logging anomalies from their own security tooling, not just trusting it, and anyone running a disclosure programme should read this saga as a lesson in what not to do.
Also this week
Supply chain. Researchers at Socket caught 17 npm and PyPI packages on 7 July impersonating software development kits for Paysafe, Skrill and Neteller, three payment services widely used by UK fintech and gambling platforms. The packages mimicked the real SDKs closely enough to return convincing success responses while quietly harvesting API keys, AWS credentials, and GitHub and npm tokens from developer machines and build pipelines, then shipping them to attacker infrastructure. Socket flagged the cluster within six minutes of the first npm upload, fast by industry standards and still not fast enough for anyone who had already pulled the package. The lesson repeats because it keeps working: verify the publisher before you trust a name that sounds official.
Ransomware claim. The Dragonforce extortion group has posted a claim against HIVE360, a UK employment administration and employee benefits specialist, threatening to publish stolen data unless contacted. HIVE360 has not confirmed the incident and the claim currently rests on the group's own dark web posting, so treat it as exactly that: a claim, not a confirmed breach. Employee benefits and payroll providers sit on precisely the sensitive financial and personal data that make double-extortion attractive, whatever the outcome of this particular case.
Policy and law. The Data (Use and Access) Act 2025's new complaints-handling rules came into force on 19 June, requiring every organisation that handles personal data, corner shop to major bank, to run a clear complaints process: acknowledge within 30 days, investigate without undue delay, and keep records the ICO can request. The ICO's deputy commissioner Emily Keaney has said there is "still plenty of time to act" but that smaller organisations are least likely to have a formal process in place already. Unlike most items in this newsletter, this one needs no patch, just a documented process and a named owner.
Sources
- Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day
- Microsoft Patches Defender 'RoguePlanet' Vulnerability
- Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
- Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
- Ransom! hive360.com (JUL-2026)
- Data (Use and Access) Act 2025: new statutory rules on handling data protection complaints from 19th June 2026
If any of this affects your organisation, get in touch.
More like this
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- The Department for Education's helpdesk, and the 607,000 records it was never built to hold 31 july 2026
- The SD-WAN orchestrator that needed no login, and the one before it 29 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.