Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft’s own fix.
ShieldBreak demonstrates a complete bypass of the patch Microsoft shipped for RoguePlanet, the Windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656, proving that the underlying weakness in the Microsoft Malware Protection Engine was never fully closed.
RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM.
Microsoft eventually acknowledged the bug, rated it “Exploitation More Likely” with a CVSS score of 7.8, and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.
The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft's own fix.
cybersecuritynews.com