Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

thehackernews+1bleepingcomputerthehackernewsA security researcher operating under the alias Nightmare Eclipse has released a proof-of-concept exploit called ShieldBreak that bypasses Microsoft's recent patch for a privilege escalation vulnerability in Windows Defender, once again granting attackers SYSTEM-level access on fully updated systems.
ShieldBreak targets CVE-2026-50656, a race condition in the Microsoft Malware Protection Engine (mpengine.dll) originally disclosed by the researcher in June 2026 under the name RoguePlanet. Microsoft patched the flaw in July, but Nightmare Eclipse claims the fix is incomplete.thehackernews+1
"Microsoft has failed to properly patch the RoguePlanet vulnerability," the researcher wrote, adding that the exploit has a "100% success rate" on the latest versions of Windows 11 25H2, the Canary channel, and Windows Server 2025. Windows 10 systems are also said to be vulnerable, though the PoC does not yet support them.bleepingcomputer+1
Will Dormann, principal vulnerability analyst at Tharros, confirmed on Tuesday that the exploit works, noting that Microsoft Defender must be enabled for ShieldBreak to escalate privileges.bleepingcomputer
The release is part of a months-long confrontation between Nightmare Eclipse and Microsoft over vulnerability disclosure and bug bounty practices. Since April 2026, the researcher has publicly dropped exploits targeting Defender, BitLocker, and other Windows components, including BlueHammer, RedSun, YellowKey, GreenPlasma, and UnDefend. Multiple exploits from this campaign have been observed in real-world intrusions.barracuda+2
Microsoft responded to the disclosures with warnings of legal action against people engaging in "malicious activity causing real harm" to its customers, which cybersecurity experts interpreted as a direct threat to the researcher.bleepingcomputer
ShieldBreak's release coincided with Microsoft's August 2026 Patch Tuesday, which addressed 421 security flaws including an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820) that also grants SYSTEM privileges. That vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 25, 2026.thehackernews
Microsoft also patched LegacyHive (CVE-2026-62832), another privilege escalation flaw previously disclosed by Nightmare Eclipse. Microsoft told The Hacker News it is aware of the ShieldBreak report and is investigating.thehackernews