Cybersecurity

Researcher defies Microsoft, releases Windows zero-day ShieldBreak

Published Aug 12, 2026, 3:24 PM2 min readNewUJ Editorial Desk

Researcher defies Microsoft, releases Windows zero-day ShieldBreak
Photo: Markus Spiske · Unsplash
0 0
XWhatsAppTelegramLinkedIn

A security researcher has published details of a new Windows vulnerability that allows attackers to gain full system access, despite Microsoft threatening legal action weeks earlier over similar disclosures. The bug, called ShieldBreak, was released by researcher Nightmare Eclipse on August 12, 2026, one day after Microsoft's monthly Patch Tuesday security updates.

ShieldBreak exploits a flaw in Windows Defender, the built-in anti-malware engine, to escalate privileges from a low-level user to full device and data access. According to Nightmare Eclipse, the proof-of-concept exploit works on Windows 10, Windows 11 including the latest 25H2 version, and Windows Server 2025, and requires the user to run a malicious app. Security researcher Will Dormann verified the exploit works, noting that Windows Defender must be enabled for it to succeed.

The disclosure matters because it is a zero-day: Microsoft had no time to patch before public release, leaving systems vulnerable. The bug builds on an earlier exploit by Nightmare Eclipse called RoguePlanet, which Microsoft patched, but the researcher claims the new exploit fully bypasses that fix. Microsoft has not yet released a patch for ShieldBreak, and a spokesperson did not immediately comment when contacted by TechCrunch.

The release continues a long-running dispute between Nightmare Eclipse and Microsoft over bug report handling. In blog posts, the researcher claimed Microsoft mistreated them and mishandled reports, implying public disclosure was the only option. Nightmare Eclipse previously released other Windows bugs later exploited in real-world attacks. In May, Microsoft published a blog post threatening legal action against researchers who disclose zero-days outside its policies, drawing heavy rebuke from the security community; Microsoft later walked back the comments on social media, but the original post remains unchanged.

ShieldBreak lands a day after Microsoft's August 2026 Patch Tuesday, the second consecutive month with around 500 patches driven by the company's growing use of AI to find security flaws. The lack of a patch for ShieldBreak means organizations running affected Windows versions remain exposed until Microsoft responds.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.