Urgent.News

What's breaking now, across thousands of outlets.

Tech

ShieldCrash: A Second Path Around the Microsoft Defender ShieldBreak Fix

ShieldCrash: A Second Path Around the Microsoft Defender ShieldBreak Fix On 9 September 2026, an anonymous researcher publishing as Nightmare Eclipse released a proof of concept named ShieldCrash. It targets Microsoft Defender and it reaches NT AUTHORITY\SYSTEM level file reads on Windows hosts that have taken the September 2026 cumulative update in full. The technique is a bypass, not a fresh…

On September 9, 2026, an anonymous researcher known as Nightmare Eclipse unveiled a proof of concept dubbed ShieldCrash. This exploit targets Microsoft Defender, granting NT AUTHORITY\SYSTEM level file reads on Windows systems that have installed the September 2026 cumulative update. The bypass does not introduce a new class of bugs; instead, it re-enters the privilege boundary that Microsoft attempted to close.

The vulnerability, tracked as CVE-2026-69414, is assigned a CVSS base score of 7.8. Microsoft's security team patched the primary exploitation path, but Nightmare Eclipse claimed that the fix only closed the conditions for the original technique, leaving one location accessible for triggering the underlying problem. The bypass employs a combination of Windows mechanisms, including object manager symbolic links, content switching through the Cloud Filter API, and CLFS namespaces, along with a race condition between Defender scanning a file and acting on it.

Upon successful exploitation, ShieldCrash allows for SYSTEM-level arbitrary file read, granting access to protected system configuration, credential material, and sensitive data. While arbitrary write and full code execution have not been confirmed, the ability to read what the highest-privileged account can read remains a valuable escalation and reconnaissance step for attackers who already hold local code execution.

Two sources describe the affected engine versions differently - one mentions engine version 1.1.26080.3, while another states that hosts with version 1.1.26060.3008 and later are still vulnerable. Until an official fix is released, administrators are advised to keep their Malware Protection Engine updated and enable cloud protection.

A temporary workaround involves creating a zero-byte file at the path Defender would otherwise use, though this addresses only the demonstrated technique. The researcher and Microsoft continue to clash over vulnerability disclosure practices, with the researcher disclosing multiple issues since April 2026, of which Microsoft has patched some and left others unaddressed.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

5 Skills I Still Learn by Hand While Agents Write Code

Two things landed on Hacker News this week that look unrelated and are not. First, an essay called "The death of web development education" made the front page with a hundred-plus comments arguing…

  • Quickly reading diffs to identify dangerous patterns and unchecked inputs
  • Breaking work into small, testable units to enhance agent-assisted development
  • Debugging from first principles to resolve agent-suggested issues

AWS EKS deploy - Live Demo

Deploying an app to Kubernetes on AWS, with AI as my pair engineer Before AI, you'd settle on one infrastructure design up front and then build it.

  • AWS EKS used to deploy Spring Boot application
  • Claude AI pair engineer assisted in workflow
  • Scripts and documentation refined for smooth runs

Generate an SSH Key: A Practical OpenSSH Walkthrough

An SSH key pair gives you a way to authenticate to servers and Git hosting without sending your account password. The key-generation command is the same on Windows, macOS, and Linux; the important…

  • SSH key pairs authenticate servers and Git hosting without transmitting passwords
  • Choose secure file path, protect private key, install only public key
  • Set passphrase for private key to enhance protection

Building a Zero-Jank CSS Logo Marquee

Integrating community badges, open-source repositories, and syndicated profiles into static engineering sites often creates unexpected performance bottlenecks.

  • Lightweight CSS-only marquee solution replaces heavy scripts for performance improvement
  • GPU-accelerated transforms with transform: translateX() ensure smooth infinite loop
  • Reduced motion preferences respected with media query disabling animation

More from Sunday 4 October →