A Lone Researcher Forces Microsoft’s Hand With Latest Windows Defender Flaw

A security researcher known as Nightmare Eclipse has released details of a fresh Windows zero-day that bypasses protections in the built-in Defender engine. The move comes after Microsoft warned of legal steps against uncoordinated disclosures earlier this year.
The flaw, called ShieldBreak, lets an attacker with low-level access escalate to full system control. It affects Windows 10, Windows 11 including the 25H2 update, and Windows Server 2025. Nightmare Eclipse published a working proof-of-concept as a simple app that users must run themselves. Will Dormann confirmed the exploit functions only when Defender stays active.
ShieldBreak builds directly on an earlier bug the same researcher named RoguePlanet. Microsoft patched that one under CVE-2026-50656. Yet the new code shows the fix left a path open. Microsoft has issued no update for ShieldBreak so far. A company spokesperson offered no immediate reply to questions.
The disclosure landed one day after Microsoft’s August Patch Tuesday. That cycle fixed roughly 500 issues for the second month running. The volume stems in part from the company’s expanded use of AI tools to scan code. Brian Krebs noted the high count in his coverage of the rollout.
But the pattern of public drops did not start yesterday. Nightmare Eclipse has shared multiple Windows flaws over recent months. Some of those earlier issues later appeared in attacks against organizations. The researcher has long claimed Microsoft ignored or mishandled reports sent through official channels and even revoked access to its bug-reporting portal.
Microsoft pushed back in May. The company published a blog post stating that disclosures outside coordinated channels were never justifiable. It referenced its Digital Crimes Unit and possible law-enforcement involvement. The post drew sharp criticism from security researchers who described similar frustrations with response times and access. Microsoft later clarified on social media that it had no plans to pursue individual researchers. Its original blog entry remains unchanged.
TechCrunch reported the latest exchange and linked to Nightmare Eclipse’s post on the new bug. The researcher’s earlier TechCrunch coverage detailed the prior threats and the community reaction. Related reporting from The Record covered Microsoft’s subsequent softening of the legal stance.
Zero-days released this way leave organizations exposed until a fix arrives. Enterprises running the latest Windows versions now face an unpatched path to full device compromise through the security software meant to protect them. The back-and-forth between one persistent finder and the world’s largest software maker shows no sign of slowing.
So the question lingers for defenders. How many more such bypasses sit undiscovered while the patch count climbs?