Disgruntled security researcher just dropped another Windows zero-day, right on schedule

Alfonso Maruccia

Posts: 2,751   +1,078
Staff
Sounding off: NightmareEclipse did it again. The security researcher who's been on a crusade against Microsoft has published a new zero-day flaw affecting all supported Windows versions. Redmond threatened to sue, but the researcher is keeping his promise to disclose a new dangerous flaw after every month's Patch Tuesday.

NightmareEclipse and Microsoft keep clashing over zero-day vulnerabilities in Windows. The researcher, who pledged to give Redmond security hell, is back with ShieldBreak, a new flaw in Windows Defender that can be abused to gain complete, unfettered access to a Windows device and all its data.

The researcher described the latest flaw as a "funny bug" related to RoguePlanet, a previously disclosed vulnerability tracked as CVE-2026-50656. Microsoft released a fix for RoguePlanet in July, but NightmareEclipse now says the "official" patch fails to properly address the issue in Defender's end-point antivirus engine.

ShieldBreak comes with a proof-of-concept demonstration that, according to NightmareEclipse, can fully bypass Microsoft's patch to gain complete user authority over a Windows machine. External researchers confirmed that both the ShieldBreak flaw and the POC are legitimate, although they might not be related to the RoguePlanet bug in the way NightmareEclipse claims.

The POC code was tested against up-to-date versions of Windows 11 25H2 and Windows Server 2025. It boasts a "100% success rate," the researcher said, and can even work against unsupported operating systems, including both consumer and server editions of Windows 10. NightmareEclipse released the ShieldBreak details just in time for this month's Patch Tuesday, giving Microsoft essentially no time to analyze the new bug.

Redmond said it's now actively investigating the issue within Windows Defender, though it's still not confirming NightmareEclipse's "claims" about the bug. Microsoft and NightmareEclipse have been fighting over Windows' (in)security for months at this point.

The unknown researcher routinely discloses new and potentially dangerous flaws in Microsoft's OS code, and has even accused the company of planting a deliberate backdoor in Windows, as with the previously unveiled YellowKey bug. Microsoft has pushed back on that characterization, and its broader response to NightmareEclipse's disclosures has included the threat of a lawsuit.

After facing overwhelmingly negative feedback from the security community, Redmond walked back the lawsuit talk, though it's still unwilling to properly credit NightmareEclipse's contributions. AI-based analysis is now forcing Microsoft to fix hundreds of new bugs every month, but the zero-day flaws coming from one human, belligerent researcher might be the most insidious of all.

Permalink to story:

 
The financial damage of me being hacked could be massive. My faith in microslop keeps getting worse. It may be time to abandon windows for anything other than gaming...
 
The thing people don't realize is that the NSA, CIA, and other US government entities have been forcing Microsoft and other giant tech companies to keep backdoors in their OS for decades. Otherwise, how will they mass survale and archive everything that end points are doing around the globe?

They use non-disclosure agreements, so companies aren't allowed to talk about that. Edward Snowden spoke about this at great length. With this, and the new advent of AI finding zero day's with ease, these clandestine government surveillance programs aren't going to be able to collect and archive as much of what's going on as easily, and I'm sure they're concerned about that.
 
Yeah Microsoft, I'm sure threatening this security researcher will make the others world-wide want to submit their findings to Microsoft in record numbers! Such P.R geniuses!!
 
You know this is what AI should have been used for in the 1st place making better more secure software but NOOOO we use it to make nude foto's of famous people instead.. This why I hate AI on anything it should never have been allowed out of the lab it's just not ready for prime time usage by normies
 
You know this is what AI should have been used for in the 1st place making better more secure software but NOOOO we use it to make nude foto's of famous people instead.. This why I hate AI on anything it should never have been allowed out of the lab it's just not ready for prime time usage by normies
Perhaps you could ask AI to spell check your rants, so you don't spell "photo" as..."foto".
The thing people don't realize is that the NSA, CIA, and other US government entities have been forcing Microsoft and other giant tech companies to keep backdoors in their OS for decades. Otherwise, how will they mass survale and archive everything that end points are doing around the globe?

They use non-disclosure agreements, so companies aren't allowed to talk about that. Edward Snowden spoke about this at great length. With this, and the new advent of AI finding zero day's with ease, these clandestine government surveillance programs aren't going to be able to collect and archive as much of what's going on as easily, and I'm sure they're concerned about that.
If they have all these amazing backdoors, why can they not find anything they are looking for? How can basic device encryption stop them? Some thing smells....smelly.
 
The thing people don't realize is that the NSA, CIA, and other US government entities have been forcing Microsoft and other giant tech companies to keep backdoors in their OS for decades. Otherwise, how will they mass survale and archive everything that end points are doing around the globe?

They use non-disclosure agreements, so companies aren't allowed to talk about that. Edward Snowden spoke about this at great length. With this, and the new advent of AI finding zero day's with ease, these clandestine government surveillance programs aren't going to be able to collect and archive as much of what's going on as easily, and I'm sure they're concerned about that.
All, but Apple. They're a big NO
 
Perhaps you could ask AI to spell check your rants, so you don't spell "photo" as..."foto".
Maybe if your Grandmother taught you how to suck eggs you wouldn't feel the need to criticize other people's posts as you obviously knew what was meant by the wrong spelling of Photo did you really need to be a jackoff about it
 
Maybe if your Grandmother taught you how to suck eggs you wouldn't feel the need to criticize other people's posts as you obviously knew what was meant by the wrong spelling of Photo did you really need to be a jackoff about it
Problem lies with the one who can't just quietly amend his post and rectify the incorrect spelling, and has to get into a hissy fit over it. And do you know what punctuation is?

Just because "it's the internet", we get to dumb down our language usage? No sir, that's anti-civilisation, sir.
 
Problem lies with the one who can't just quietly amend his post and rectify the incorrect spelling, and has to get into a hissy fit over it. And do you know what punctuation is?

Just because "it's the internet", we get to dumb down our language usage? No sir, that's anti-civilisation, sir.
Like me my mother used to say, stop worrying about what others are doing or aren't doing, because you've got plenty to worry about yourself...
 
Back