Disgruntled security researcher just dropped another Windows zero-day, right on schedule
Key Points:
- Security researcher NightmareEclipse has disclosed a new zero-day vulnerability called ShieldBreak in Windows Defender, affecting all supported Windows versions and allowing full control over a Windows device.
- The flaw is related to a previously patched vulnerability, RoguePlanet (CVE-2026-50656), but NightmareEclipse claims Microsoft's fix is ineffective, with a proof-of-concept demonstrating a complete bypass of the patch.
- ShieldBreak has been verified by external researchers and tested with a 100% success rate on up-to-date Windows 11 25H2 and Windows Server 2025, as well as unsupported Windows 10 versions.
- Microsoft is investigating the issue but has not confirmed the researcher's claims, while continuing its ongoing dispute with NightmareEclipse, who has accused the company of deliberately planting backdoors in Windows.
- The researcher released ShieldBreak details just before Patch Tuesday, leaving Microsoft little time to respond, and Microsoft has threatened legal action in response to NightmareEclipse's disclosures.