Sounding off: NightmareEclipse did it again. The security researcher who's been on a crusade against Microsoft has published a new zero-day flaw affecting all supported Windows versions. Redmond threatened to sue, but the researcher is keeping his promise to disclose a new dangerous flaw after every month's Patch Tuesday.

NightmareEclipse and Microsoft keep clashing over zero-day vulnerabilities in Windows. The researcher, who pledged to give Redmond security hell, is back with ShieldBreak, a new flaw in Windows Defender that can be abused to gain complete, unfettered access to a Windows device and all its data.

The researcher described the latest flaw as a "funny bug" related to RoguePlanet, a previously disclosed vulnerability tracked as CVE-2026-50656. Microsoft released a fix for RoguePlanet in July, but NightmareEclipse now says the "official" patch fails to properly address the issue in Defender's end-point antivirus engine.

ShieldBreak comes with a proof-of-concept demonstration that, according to NightmareEclipse, can fully bypass Microsoft's patch to gain complete user authority over a Windows machine. External researchers confirmed that both the ShieldBreak flaw and the POC are legitimate, although they might not be related to the RoguePlanet bug in the way NightmareEclipse claims.

The POC code was tested against up-to-date versions of Windows 11 25H2 and Windows Server 2025. It boasts a "100% success rate," the researcher said, and can even work against unsupported operating systems, including both consumer and server editions of Windows 10. NightmareEclipse released the ShieldBreak details just in time for this month's Patch Tuesday, giving Microsoft essentially no time to analyze the new bug.

Redmond said it's now actively investigating the issue within Windows Defender, though it's still not confirming NightmareEclipse's "claims" about the bug. Microsoft and NightmareEclipse have been fighting over Windows' (in)security for months at this point.

The unknown researcher routinely discloses new and potentially dangerous flaws in Microsoft's OS code, and has even accused the company of planting a deliberate backdoor in Windows, as with the previously unveiled YellowKey bug. Microsoft has pushed back on that characterization, and its broader response to NightmareEclipse's disclosures has included the threat of a lawsuit.

After facing overwhelmingly negative feedback from the security community, Redmond walked back the lawsuit talk, though it's still unwilling to properly credit NightmareEclipse's contributions. AI-based analysis is now forcing Microsoft to fix hundreds of new bugs every month, but the zero-day flaws coming from one human, belligerent researcher might be the most insidious of all.