Researcher defies Microsoft, releases Windows zero-day ShieldBreak
A security researcher has published details of a new Windows vulnerability that allows attackers to gain full system access, despite Microsoft threatening legal action weeks earlier over similar disclosures. The bug, called ShieldBreak, was released by researcher Nightmare Eclipse on August 12, 2026, one day after Microsoft's monthly Patch Tuesday security updates.
ShieldBreak exploits a flaw in Windows Defender, the built-in anti-malware engine, to escalate privileges from a low-level user to full device and data access. According to Nightmare Eclipse, the proof-of-concept exploit works on Windows 10, Windows 11 including the latest 25H2 version, and Windows Server 2025, and requires the user to run a malicious app. Security researcher Will Dormann verified the exploit works, noting that Windows Defender must be enabled for it to succeed.
The disclosure matters because it is a zero-day: Microsoft had no time to patch before public release, leaving systems vulnerable. The bug builds on an earlier exploit by Nightmare Eclipse called RoguePlanet, which Microsoft patched, but the researcher claims the new exploit fully bypasses that fix. Microsoft has not yet released a patch for ShieldBreak, and a spokesperson did not immediately comment when contacted by TechCrunch.
The release continues a long-running dispute between Nightmare Eclipse and Microsoft over bug report handling. In blog posts, the researcher claimed Microsoft mistreated them and mishandled reports, implying public disclosure was the only option. Nightmare Eclipse previously released other Windows bugs later exploited in real-world attacks. In May, Microsoft published a blog post threatening legal action against researchers who disclose zero-days outside its policies, drawing heavy rebuke from the security community; Microsoft later walked back the comments on social media, but the original post remains unchanged.
ShieldBreak lands a day after Microsoft's August 2026 Patch Tuesday, the second consecutive month with around 500 patches driven by the company's growing use of AI to find security flaws. The lack of a patch for ShieldBreak means organizations running affected Windows versions remain exposed until Microsoft responds.
Sources
- TechCrunchSecondary
Related
Uber Freight probes data breach claim by Helix hackers
Zoom flaws let attackers hijack devices via screen sharing
Coin-Sized Device Hacks Boeing 737 Autopilot in 60 Seconds
Hackers vishing financial firm staff to extort victims, Google says
LightSpy spyware targets victims in 13 countries, including US
Hacker pleads guilty to stealing data from 165+ Snowflake customers
Hackers target 30 US water systems via exposed controllers
Meta AI model hacks outside system during cybersecurity test
Trending now
- US inflation eases to 3.4% as food costs cool
- CPI rises 0.1% in July, annual inflation at 3.4%
- Fungus kills African armyworm, offering hope to farmers
- Uber Freight probes data breach claim by Helix hackers
- Google Pixel 11 starts at $899 with doubled storage
- Tesla plans $10B solar factory in Texas
- Hydrogen car breaks land speed record at 406 mph
- NASA Astronaut Mike Fincke Departs After 30 Years, 549 Days in Space
Comments
No comments yet. Be the first.