After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
Security researcher Nightmare Eclipse has released details of a vulnerability dubbed ShieldBreak in recent versions of Windows. This exploit allows hackers to gain full access to a device and its data, despite Microsoft’s earlier legal threat over the disclosure of similar flaws. The bug takes advantage of a flaw in Windows Defender, the built-in anti-malware on Windows.
To exploit the vulnerability, a user must run a proof-of-concept exploit as a Windows app. ShieldBreak works on Windows 10, 11, and Server 2025, provided Windows Defender is enabled. Will Dormann, another security researcher, confirmed the bug’s validity and that Windows Defender is necessary for the attack. Microsoft released a patch for a previous exploit called RoguePlanet, but Nightmare Eclipse claims their latest exploit bypasses that fix.
Microsoft has not yet released a patch for ShieldBreak and is reportedly investigating the claims. This release comes the day after Microsoft's monthly security patch release, Patch Tuesday, and is the second month in a row with around 500 patches due to the company's increased use of AI to identify and eliminate security flaws.
Microsoft previously threatened legal action against security researchers who disclosed zero-day vulnerabilities outside of the company's disclosure policies, but faced significant backlash from the security community.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.