Sounding off: NightmareEclipse did it once more. The safety researcher who’s been on a campaign towards Microsoft has revealed a brand new zero-day flaw affecting all supported Home windows variations. Redmond threatened to sue, however the researcher is protecting his promise to reveal a brand new harmful flaw after each month’s Patch Tuesday.
NightmareEclipse and Microsoft hold clashing over zero-day vulnerabilities in Home windows. The researcher, who pledged to present Redmond safety hell, is again with ShieldBreak, a brand new flaw in Home windows Defender that may be abused to achieve full, unfettered entry to a Home windows system and all its information.
The researcher described the newest flaw as a “humorous bug” associated to RoguePlanet, a beforehand disclosed vulnerability tracked as CVE-2026-50656. Microsoft launched a repair for RoguePlanet in July, however NightmareEclipse now says the “official” patch fails to correctly handle the difficulty in Defender’s end-point antivirus engine.

ShieldBreak comes with a proof-of-concept demonstration that, based on NightmareEclipse, can absolutely bypass Microsoft’s patch to achieve full person authority over a Home windows machine. Exterior researchers confirmed that each the ShieldBreak flaw and the POC are legit, though they won’t be associated to the RoguePlanet bug in the way in which NightmareEclipse claims.
The POC code was examined towards up-to-date variations of Home windows 11 25H2 and Home windows Server 2025. It boasts a “100% success charge,” the researcher stated, and may even work towards unsupported working techniques, together with each shopper and server editions of Home windows 10. NightmareEclipse launched the ShieldBreak particulars simply in time for this month’s Patch Tuesday, giving Microsoft primarily no time to research the brand new bug.
Redmond stated it is now actively investigating the difficulty inside Home windows Defender, although it is nonetheless not confirming NightmareEclipse’s “claims” in regards to the bug. Microsoft and NightmareEclipse have been preventing over Home windows’ (in)safety for months at this level.

The unknown researcher routinely discloses new and probably harmful flaws in Microsoft’s OS code, and has even accused the corporate of planting a deliberate backdoor in Home windows, as with the beforehand unveiled YellowKey bug. Microsoft has pushed again on that characterization, and its broader response to NightmareEclipse’s disclosures has included the specter of a lawsuit.
After going through overwhelmingly unfavorable suggestions from the safety group, Redmond walked again the lawsuit discuss, although it is nonetheless unwilling to correctly credit score NightmareEclipse’s contributions. AI-based evaluation is now forcing Microsoft to repair tons of of latest bugs each month, however the zero-day flaws coming from one human, belligerent researcher could be essentially the most insidious of all.
