Bleepingcomputer
New ShieldBreak Zero-Day Exploit Bypasses Microsoft Defender Patch
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A security researcher known as Nightmare Eclipse has released a zero-day exploit named ShieldBreak, which bypasses the patch for the RoguePlanet vulnerability (CVE-2026-50656) in Microsoft Defender. This exploit allows attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The proof of concept (PoC) has a 100% success rate when tested on the latest Windows 11 and Windows Server 2025 versions. Microsoft had previously patched RoguePlanet in July 2026, but Nightmare Eclipse claims that the patch was insufficient. The exploit is part of an ongoing dispute between the researcher and Microsoft regarding vulnerability disclosures. Microsoft has warned of potential legal action against individuals engaging in malicious activities. Other vulnerabilities disclosed by Nightmare Eclipse remain unpatched. Cybersecurity experts are concerned about the implications of this exploit for users of Microsoft Defender.
Key Points: • ShieldBreak exploits a bypass in Microsoft Defender's RoguePlanet patch. • The exploit grants SYSTEM-level access on fully patched Windows systems. • Microsoft has issued warnings of legal action against the researcher behind the exploit.