After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

2 days ago 11
Windows logo connected  a acheronian  bluish  background.Image Credits:Microsoft / PhotoMosh / record photo

8:18 AM PDT · August 12, 2026

A information researcher has published details of a caller vulnerability successful the latest versions of Windows that allows hackers to summation system-wide entree to the user’s instrumentality and data, contempt facing a ineligible menace from Microsoft weeks earlier implicit the merchandise of antecedently chartless bundle flaws.

The caller bug, dubbed ShieldBreak, is the latest disclosure by information researcher Nightmare Eclipse, who successful caller months has published details of several bugs affecting Microsoft’s products, including Windows.

According to Nightmare Eclipse’s post, ShieldBreak takes vantage of a flaw successful Windows Defender, the anti-malware and information motor built into Windows. A palmy onslaught allows the hacker to escalate their permissions from a low-level idiosyncratic to afloat entree to the instrumentality and its data. 

Nightmare Eclipse published the proof-of-concept exploit arsenic a Windows app, requiring the idiosyncratic to tally the app to exploit the bug. The bug works connected Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025, the researcher said.

Security researcher Will Dormann verified that the bug works and that Windows Defender indispensable beryllium enabled for the exploit to work. 

The latest exploit builds connected an earlier exploit that Nightmare Eclipse developed dubbed RoguePlanet. Microsoft rolled retired a spot for RoguePlanet, but Nightmare Eclipse implied that Microsoft’s hole was not capable and that their latest exploit demonstrates a afloat bypass of the earlier patch.

Microsoft has not yet released a spot for the ShieldBreak bug. A spokesperson for Microsoft did not instantly remark erstwhile contacted by TechCrunch. The bug is considered a zero-day due to the fact that the bundle shaper — successful this case, Microsoft — was fixed nary clip to spot the bug earlier it was publically disclosed.

The merchandise of this caller zero-day is the latest successful a agelong back-and-forth betwixt the information researcher and the bundle elephantine implicit the company’s alleged handling of their bug reports. 

In a bid of blog posts, the information researcher claimed that Microsoft mistreated them and did not grip their bug reports sufficiently, with the accusation that the researcher had nary different prime but to publically disclose the bugs online. Nightmare Eclipse antecedently released respective different bugs successful Windows that were later exploited successful real-world attacks to hack into organizations.

In May, Microsoft published a blog post threatening to instrumentality ineligible enactment against information researchers, similar Nightmare Eclipse, if they released details of zero-days extracurricular of the company’s disclosure policies. The institution faced dense rebuke from the information community, galore of whom described akin experiences with Microsoft’s handling of their bug reports. Microsoft aboriginal walked backmost the comments successful a societal media post. Its archetypal blog station remains published and unchanged.

ShieldBreak lands a time aft Microsoft’s regularly scheduled monthly information spot releases, dubbed Patch Tuesday. This is the 2nd period successful a enactment wherever the fig of patches has reached astir 500 oregon truthful bugs driven by the company’s growing usage of AI to find and weed retired information flaws.

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.

Read Entire Article