Back Uk.Pcmag Disgruntled Researcher Discloses New Zero-Day in Windows Antivirus
A disgruntled security researcher who's been feuding with Microsoft has released a newly discovered vulnerability in Windows Defender that could be used to help hackers attack PCs. On Tuesday, the researcher, Nightmare Eclipse, announced “ShieldBreak,” describing it as a zero-day vulnerability, or a flaw that currently has no software patch. The vulnerability can’t remotely hack a Windows PC; instead, it can let an attacker who already has access elevate their privileges to the highest “system” level. To prove the threat is real, Nightmare Eclipse has released a proof-of-concept code that can exploit the bug in Windows Defender in Windows 11 25H2 and Windows Server 2025. Two security researchers, Will Dormann and Kevin Beaumont, have tried the proof-of-concept code and say it works, although Defender needs to be enabled. The result “gets you SYSTEM privileges from any user account,” Beaumont added . “I've tried it, it works on the latest Windows 11.” ShieldBreak arrives after Nightmare Eclipse disclosed a separate privilege escalation flaw, called Rogue Planet , in June that also exploited Windows Defender. a week later, Microsoft patched the threat. Now Nightmare Eclipse claims to have effectively circumvented the company’s patch through ShieldBreak by apparently leveraging a different method. The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
On Tuesday, the researcher, Nightmare Eclipse, announced “ShieldBreak,” describing it as a zero-day vulnerability, or a flaw that currently has no software patch. The vulnerability can’t remotely hack a Windows PC; instead, it can let an attacker who already has access elevate their privileges to the highest “system” level. To prove the threat is real, Nightmare Eclipse has released a proof-of-concept code that can exploit the bug in Windows Defender in Windows 11 25H2 and Windows Server 2025. Two security researchers, Will Dormann and Kevin Beaumont, have tried the proof-of-concept code and say it works, although Defender needs to be enabled. The result “gets you SYSTEM privileges from any user account,” Beaumont added . “I've tried it, it works on the latest Windows 11.” ShieldBreak arrives after Nightmare Eclipse disclosed a separate privilege escalation flaw, called Rogue Planet , in June that also exploited Windows Defender. a week later, Microsoft patched the threat. Now Nightmare Eclipse claims to have effectively circumvented the company’s patch through ShieldBreak by apparently leveraging a different method. The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
To prove the threat is real, Nightmare Eclipse has released a proof-of-concept code that can exploit the bug in Windows Defender in Windows 11 25H2 and Windows Server 2025. Two security researchers, Will Dormann and Kevin Beaumont, have tried the proof-of-concept code and say it works, although Defender needs to be enabled. The result “gets you SYSTEM privileges from any user account,” Beaumont added . “I've tried it, it works on the latest Windows 11.” ShieldBreak arrives after Nightmare Eclipse disclosed a separate privilege escalation flaw, called Rogue Planet , in June that also exploited Windows Defender. a week later, Microsoft patched the threat. Now Nightmare Eclipse claims to have effectively circumvented the company’s patch through ShieldBreak by apparently leveraging a different method. The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
Two security researchers, Will Dormann and Kevin Beaumont, have tried the proof-of-concept code and say it works, although Defender needs to be enabled. The result “gets you SYSTEM privileges from any user account,” Beaumont added . “I've tried it, it works on the latest Windows 11.” ShieldBreak arrives after Nightmare Eclipse disclosed a separate privilege escalation flaw, called Rogue Planet , in June that also exploited Windows Defender. a week later, Microsoft patched the threat. Now Nightmare Eclipse claims to have effectively circumvented the company’s patch through ShieldBreak by apparently leveraging a different method. The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
ShieldBreak arrives after Nightmare Eclipse disclosed a separate privilege escalation flaw, called Rogue Planet , in June that also exploited Windows Defender. a week later, Microsoft patched the threat. Now Nightmare Eclipse claims to have effectively circumvented the company’s patch through ShieldBreak by apparently leveraging a different method. The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
The big question is whether Microsoft will retaliate against Nightmare Eclipse, who also discovered another zero-day privilege escalation flaw called BlueHammer . In May, the company subtly threatened legal consequences for anyone who put “proof-of-concept code for unpatched vulnerabilities into the hands of bad actors,” without any effort to coordinate with Microsoft. The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
The company dialed back its original threat following some backlash from the cybersecurity community. "To be clear our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate," Microsoft tweeted . In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
In response to the newly-disclosed ShieldBreak flaw, Microsoft merely told PCMag that it's aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
Nightmare Eclipse appears to be a security researcher who formerly worked for Microsoft, uncovering software bugs. However, the bug hunter has been deliberately avoiding attempts to coordinate with Microsoft to patch the vulnerabilities, citing past mistreatment by the company. “Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
“Considering the recent events with Microsoft, I was thinking a lot trying fentanyl, I know lots of you would say this is insanely stupid but hear me out Microsoft would turn me into a robot if I actually die,” Nightmare Eclipse posted last month.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
