Disgruntled Security Researcher Just Dropped Another Windows Zero-Day, Right on Schedule
Security researcher Will Dormann confirmed the flaw works, and Microsoft says it is actively investigating a bug that could grant full system access.
- A new security vulnerability called ShieldBreak targets Windows Defender, the built-in anti-malware engine on Windows and Windows Server. If exploited, the bug allows attackers to escalate privileges from low-level user accounts to full system access.
- Security researcher Nightmare Eclipse published the proof of concept despite Microsoft's legal threats issued in May. The vulnerability reportedly builds on an earlier exploit known as RoguePlanet.
- The proof of concept is a downloadable app, meaning the exploit requires a user to manually run it. No patch currently exists to address the flaw.
- Microsoft is aware of the reported vulnerability and is actively investigating. Security researcher Will Dormann confirmed the bug works when Windows Defender is enabled.
- Users should monitor for potential security updates, as no patch exists yet to address the flaw. This underscores ongoing tensions between software developers and security researchers over zero-day disclosure practices.
23 Articles
23 Articles
Researcher Defies Microsoft Legal Threat, Drops Unpatched Windows Defender Exploit – channelnews
Windows, WindA security researcher has publicly released an unpatched Windows exploit dubbed “nasty” by observers, openly defying Microsoft after the Company threatened legal action against researchers who disclose bugs outside its rules. The researcher, known as Nightmare Eclipse, has published a proof-of-concept for ShieldBreak, a flaw targeting Windows Defender, the anti-malware engine built into every copy of Windows. Successfully exploited, ShieldBreak lets an attacker escalate from a low-level user account to full system access, effectively handing over the keys to the entire machine. The exploit affects Windows 10, Windows 11 and Windows Server 2025, according to the researcher. Fellow security researcher Will Dormann has confirmed the bug works. The proof of concept was released as a downloadable Windows app, meaning a target would need to run it for the exploit to fire. No patch exists. Microsoft says it is “aware of the reported vulnerability and is actively investigating.” Feud Boils Over The release is the latest salvo in a long-running feud between Nightmare Eclipse and Microsoft over how the Company handles bug reports, with the researcher accusing Microsoft of mishandling previous disclosures, resulting in several bugs being published publicly rather than quietly patched. ShieldBreak reportedly builds on an earlier exploit from the same researcher, RoguePlanet. Microsoft patched that flaw, but Nightmare Eclipse claims the fix fell short and that ShieldBreak fully bypasses it. In May, Microsoft inflamed tensions by threatening legal action against researchers who go public with zero-days outside its disclosure rules. The security community pushed back hard, and Microsoft softened its stance on social media, though the original blog post remains live. Vulnerabilities Double As Prices Rise The disclosure lands as Microsoft battles a bug infestation across multiple products while simultaneously raising prices for both B2B and consumer software. Total Microsoft critical vulnerabilities have doubled to 157, reversing more than a decade of steady improvement, according to BeyondTrust’s annual report. Windows accounted for 612 CVEs and Windows Server 780, remaining the largest sources of vulnerabilities. Azure and Dynamics 365 vulnerabilities plateaued at 69 in 2025, but critical flaws hit a record high, jumping from 4 to 37, a 9x surge. Elevation of Privilege flaws, the same class as ShieldBreak, made up 40% of all 2025 vulnerabilities, giving attackers a fast path from a foothold to full control, analysts claim. Patch Tuesdays have ballooned in 2026. July’s update alone addressed 622 vulnerabilities across Windows, Office, SharePoint Server, AD FS, Exchange, Azure components and SQL Server, including two flaws actively exploited in the wild, an AD FS privilege escalation (CVE-2026-56155) and a SharePoint Server privilege escalation (CVE-2026-56164). The SharePoint bug was particularly nasty, remotely exploitable without authentication and raising the risk to internet-facing servers. Three Converging Pressures Microsoft is facing an identity-centric threat model, with state-sponsored attacks now targeting credentials rather than just zero-days and more password spraying and token theft expected. AI is cutting both ways, accelerating vulnerability discovery for defenders and attackers alike and shrinking the gap between disclosure and exploitation. The Company is also under ongoing reputational and regulatory heat from governments after repeated federal-system compromises. In response, Microsoft has moved every Microsoft Account and Entra ID token-signing key into hardware security modules or Azure confidential VMs with automatic rotation under its Secure Future Initiative, an implicit admission of the key-management failures behind the Storm-0558 debacle. For Windows users, with no ShieldBreak patch available, this is one to watch.
The ShieldBreak vulnerability is one of the most prominent security flaws recently discovered in Microsoft Defender, allowing for bypassing security updates and gaining access to the operating system. A proof of concept (PoC) for the ShieldBreak vulnerability in Microsoft Defender has been released by the security researcher known as Chaotic Eclipse (also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse). Details of the vulnerabil…
Disgruntled security researcher just dropped another Windows zero-day, right on schedule
NightmareEclipse and Microsoft keep clashing over zero-day vulnerabilities in Windows. The researcher, who pledged to give Redmond security hell, is back with ShieldBreak, a new flaw in Windows Defender that can be abused to gain complete, unfettered access to a Windows device and all its data.Read Entire Article
Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users
Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑dayFlaw bypasses a recent patch and works on fully updated Windows 11 systemsResearcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatchedNightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and release…
Microsoft in race against time with scammers to fix 2 critical flaws in Windows — how to protect your PC now
Your Windows 11 PC could be at risk of malware. A new "zero-day vulnerability" known as CVE-2026-68820 has been found to be exploiting Windows PCs. Experts say this type of flaw is extra worrisome as hackers have already discovered the glitch and will be leveraging it to hack into devices worldwide.And this particular bug is in a networking component of Windows that lets attackers who have already gained basic access to your PC escalate their pr…
Coverage Details
Bias Distribution
- 71% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium


















