Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Exploit Wednesday's back, baby

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Nightmare Eclipse, a hacker with a grudge against Microsoft, has released a new zero-day vulnerability called ShieldBreak. This exploit can give attackers SYSTEM privileges on fully patched versions of Windows 10, Windows 11, and Windows Server. Kevin Beaumont, a former Microsoft employee and security expert, confirmed that ShieldBreak works on the latest Windows 11 systems.

This is the tenth zero-day exploit published by Nightmare Eclipse since their attack began in early April. They suspect the hacker is a disgruntled former Microsoft employee. Despite Microsoft patching 421 security issues during Patch Tuesday, ShieldBreak remains unpatched. It is a local privilege escalation exploit that targets Defender's cloud-hydration scan via the Cloud Filter API.

ShieldBreak works by performing a user-mode callback hook to change file contents during the scan. While Nightmare claims the exploit is a patch bypass for CVE-2026-50656, security researcher Kevin Beaumont states that the two flaws operate differently. Microsoft has not yet commented on the new vulnerability.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Wednesday 12 August →