Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows
Exploit Wednesday's back, baby
Nightmare Eclipse, a hacker with a vendetta against Microsoft, has released a new zero-day exploit called ShieldBreak. This exploit allows attackers to gain SYSTEM-level privileges on fully patched Windows 10, Windows 11, and Windows Server systems. Kevin Beaumont, a former Microsoft employee and security expert, confirmed that ShieldBreak works on the latest version of Windows 11.
The exploit is a local privilege escalation vulnerability, different from the previously disclosed RoguePlanet vulnerability, which was a filesystem race condition. Nightmare Eclipse, suspected to be a former disgruntled Microsoft employee, has published 10 zero-days targeting Microsoft since early April. ShieldBreak bypasses the recently patched CVE-2026-50656, but is still vulnerable to attack on Windows 10 and Server editions. Microsoft has not commented on the new exploit or when it plans to release a patch.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.