Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Disgruntled Security Researcher Just Dropped Another Windows Zero-Day, Right on Schedule

Security researcher Will Dormann confirmed the flaw works, and Microsoft says it is actively investigating a bug that could grant full system access.

  • A new security vulnerability called ShieldBreak targets Windows Defender, the built-in anti-malware engine on Windows and Windows Server. If exploited, the bug allows attackers to escalate privileges from low-level user accounts to full system access.
  • Security researcher Nightmare Eclipse published the proof of concept despite Microsoft's legal threats issued in May. The vulnerability reportedly builds on an earlier exploit known as RoguePlanet.
  • The proof of concept is a downloadable app, meaning the exploit requires a user to manually run it. No patch currently exists to address the flaw.
  • Microsoft is aware of the reported vulnerability and is actively investigating. Security researcher Will Dormann confirmed the bug works when Windows Defender is enabled.
  • Users should monitor for potential security updates, as no patch exists yet to address the flaw. This underscores ongoing tensions between software developers and security researchers over zero-day disclosure practices.
Insights by Ground AI

23 Articles

Center

Researcher Defies Microsoft Legal Threat, Drops Unpatched Windows Defender Exploit – channelnews

Windows, WindA security researcher has publicly released an unpatched Windows exploit dubbed “nasty” by observers, openly defying Microsoft after the Company threatened legal action against researchers who disclose bugs outside its rules. The researcher, known as Nightmare Eclipse, has published a proof-of-concept for ShieldBreak, a flaw targeting Windows Defender, the anti-malware engine built into every copy of Windows. Successfully exploited, ShieldBreak lets an attacker escalate from a low-level user account to full system access, effectively handing over the keys to the entire machine. The exploit affects Windows 10, Windows 11 and Windows Server 2025, according to the researcher. Fellow security researcher Will Dormann has confirmed the bug works. The proof of concept was released as a downloadable Windows app, meaning a target would need to run it for the exploit to fire. No patch exists. Microsoft says it is “aware of the reported vulnerability and is actively investigating.” Feud Boils Over The release is the latest salvo in a long-running feud between Nightmare Eclipse and Microsoft over how the Company handles bug reports, with the researcher accusing Microsoft of mishandling previous disclosures, resulting in several bugs being published publicly rather than quietly patched. ShieldBreak reportedly builds on an earlier exploit from the same researcher, RoguePlanet. Microsoft patched that flaw, but Nightmare Eclipse claims the fix fell short and that ShieldBreak fully bypasses it. In May, Microsoft inflamed tensions by threatening legal action against researchers who go public with zero-days outside its disclosure rules. The security community pushed back hard, and Microsoft softened its stance on social media, though the original blog post remains live. Vulnerabilities Double As Prices Rise The disclosure lands as Microsoft battles a bug infestation across multiple products while simultaneously raising prices for both B2B and consumer software. Total Microsoft critical vulnerabilities have doubled to 157, reversing more than a decade of steady improvement, according to BeyondTrust’s annual report. Windows accounted for 612 CVEs and Windows Server 780, remaining the largest sources of vulnerabilities. Azure and Dynamics 365 vulnerabilities plateaued at 69 in 2025, but critical flaws hit a record high, jumping from 4 to 37, a 9x surge. Elevation of Privilege flaws, the same class as ShieldBreak, made up 40% of all 2025 vulnerabilities, giving attackers a fast path from a foothold to full control, analysts claim. Patch Tuesdays have ballooned in 2026. July’s update alone addressed 622 vulnerabilities across Windows, Office, SharePoint Server, AD FS, Exchange, Azure components and SQL Server, including two flaws actively exploited in the wild, an AD FS privilege escalation (CVE-2026-56155) and a SharePoint Server privilege escalation (CVE-2026-56164). The SharePoint bug was particularly nasty, remotely exploitable without authentication and raising the risk to internet-facing servers. Three Converging Pressures Microsoft is facing an identity-centric threat model, with state-sponsored attacks now targeting credentials rather than just zero-days and more password spraying and token theft expected. AI is cutting both ways, accelerating vulnerability discovery for defenders and attackers alike and shrinking the gap between disclosure and exploitation. The Company is also under ongoing reputational and regulatory heat from governments after repeated federal-system compromises. In response, Microsoft has moved every Microsoft Account and Entra ID token-signing key into hardware security modules or Azure confidential VMs with automatic rotation under its Secure Future Initiative, an implicit admission of the key-management failures behind the Storm-0558 debacle. For Windows users, with no ShieldBreak patch available, this is one to watch.

Lean Right

The ShieldBreak vulnerability is one of the most prominent security flaws recently discovered in Microsoft Defender, allowing for bypassing security updates and gaining access to the operating system. A proof of concept (PoC) for the ShieldBreak vulnerability in Microsoft Defender has been released by the security researcher known as Chaotic Eclipse (also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse). Details of the vulnerabil…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 71% of the sources are Center
71% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Fredzone broke the news on Wednesday, August 12, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal