The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a PoC for ShieldBreak, a Microsoft Defender zero-day. The flaw bypasses the patch for CVE-2026-50656 (RoguePlanet), a race condition that can allow attackers to spawn a SYSTEM-level shell. Successful exploitation could enable arbitrary code execution and other unauthorized actions on affected Windows systems. “Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass.” said Chaotic Eclipse. “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.” In early July, Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection Engine used by Defender. The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal functions. The flaw is a local privilege escalation issue that could allow an attacker with access to a system to obtain higher privileges and potentially compromise security controls. In mid-June, Microsoft acknowledged the RoguePlanet zero-day affecting Microsoft Defender and stated it is aware of the issue and was actively developing a security update to address the flaw and protect affected systems. A week before, the security researcher Chaotic Eclipse published a new proof-of-concept exploit for a RoguePlanet. The flaw relies on a race condition that can provide attackers with SYSTEM-level privileges, allowing them to execute code with the highest permissions. The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates, showing that patched systems may still be vulnerable. Now Chaotic Eclipse claims ShieldBreak fully bypasses Microsoft’s CVE-2026-50656 patch, while Defender may also leak 8 bytes of data under certain conditions. The researcher tested the PoC on Windows 11 25H2 and Windows Server 2025 with a 100% success rate. Windows 10 is also vulnerable, though not currently supported by the PoC. In May, the researcher disclosed two other Windows zero-day vulnerabilities named YellowKey and GreenPlasma. The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON). YellowKey could allow attackers to bypass BitLocker protections, while GreenPlasma enables privilege escalation. The researcher previously disclosed three Microsoft Defender vulnerabilities. The researcher criticized Microsoft for revoking access to their MSRC account, rejecting reports, and failing to provide compensation. At the end of May, Microsoft’s Security Response Center called the zero-day dumps irresponsible. “In recent weeks several zero-day vulnerabilities have been publicly disclosed.” reads the report published by Microsoft. “The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.” The company said its security teams have been working around the clock since the disclosures to understand the impact, build patches, and protect customers from attackers who picked up the published exploit code and ran with it. Microsoft’s post is essentially a public defense of Coordinated Vulnerability Disclosure, the standard practice where a researcher notifies a vendor privately, gives them time to fix the issue, and then goes public. Microsoft says it works with hundreds of researchers this way every year, compensating them through bug bounty programs and crediting them publicly. “This partnership allows us to make updates to impacted services before proof-of-concept code can make it into the hands of bad actors.” continues the report. “The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed.” The implication is clear: when someone skips that step, real people get attacked with real tools built from the published research. In July, just hours after Microsoft’s July 2026 Patch Tuesday, Chaotic Eclipse, published a new Windows zero-day proof-of-concept called LegacyHive. This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update. LegacyHive is a local privilege escalation vulnerability. An attacker who already has code execution as a standard user can abuse the User Profile Service to load another user’s registry hive, potentially that of a local administrator, under their own profile. At the end of May, Microsoft’s Security Response Center called the zero-day dumps irresponsible. “In recent weeks several zero-day vulnerabilities have been publicly disclosed.” reads the report published by Microsoft. “The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.” The company said its security teams have been working around the clock since the disclosures to understand the impact, build patches, and protect customers from attackers who picked up the published exploit code and ran with it. Microsoft’s post is essentially a public defense of Coordinated Vulnerability Disclosure, the standard practice where a researcher notifies a vendor privately, gives them time to fix the issue, and then goes public. Microsoft says it works with hundreds of researchers this way every year, compensating them through bug bounty programs and crediting them publicly. “This partnership allows us to make updates to impacted services before proof-of-concept code can make it into the hands of bad actors.” continues the report. “The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed.” The implication is clear: when someone skips that step, real people get attacked with real tools built from the published research. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, ShieldBreak)
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. As Nightmare Eclipse explained, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass," they said. "The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well."
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver MalwareSAP Commerce Cloud CVE-2026-58231 Exploited in the WildmacOS Screen Sharing Flaw Exploited to Deploy Monero MinersGeoServer Zero-Day Is Already Being Probed. That’s the ProblemApple warned hundreds of users of mercenary spyware attacksAmnesiaStealer Gives Attackers Live Control of Victims’ macOS BrowsersChess.com Leak Exposes 7.3 Million Users – Evidence Points to ScrapingUS Authorizes Private Cyber Firms to Hack Transnational Criminal NetworksAdobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public DisclosureU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogSharePoint CVE-2026-55040 Comes Under Attack Following Public ExploitStorm-1175 Replaces Medusa With New StormEncryptor RansomwareNorth Korean Lazarus Group Uses Windows Zero-Day in Operation Dream JobCEVA Logistics Cyberattack Disrupts European Warehouses and ShipmentsChina-Linked Hackers Use AI Agents in Autonomous Attack on TaiwanKimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and EthereumShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet PatchMicrosoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code ExecutionExfilSquad Targets New Victims, Shares Data via TorrentsIran-Linked Hackers Target More US Water Infrastructure in New Jersey and AlabamaThe inconvenient truth about AI pentesting: someone has to check all the workCisco Warns of Seven ClamAV Flaws, Two With Public PoCsGym Booking Task Turns Into Real-World AI CyberattackU.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled DataWebmail CSS Attacks Expose a New Risk for AI-Powered Email Tools International Press – Newsletter Cybercrime ExfilSquad Targets New Victims, Shares Data via Torrents Israeli population registry for sale, but the data is old Before Fraud Transacts ExfilSquad Targets New Victims, Shares Data via Torrents Fake CAPTCHA, Real Business: Traffic Distribution for Hire 7.3M chess.com records leaked, and the data is real Drop Something? Don’t Worry, Someone Caught it Malware ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection Hacking Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations AI assistant hacks gym website in first known Australian autonomous cyber attack Zoomsday Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Hackers exploit macOS Screen Sharing flaw to deploy Monero miner It’s a pre-auth, stupid! A root remote command execution on macOS with M5 in 2026? Intelligence and Information Warfare Follow-Up Analysis of the 29 December 2025 Energy Sector Incident New Jersey, Alabama Join States Targeted in Water Cyberattacks Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit Social engineering performed by UAC-0145: compromising in the employment process Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved Cybersecurity How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta Responding to the next frontier of critical cyber capabilities Facebook is paying controversial creators to produce rage-bait content Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC The August 2026 Security Update Review Cyberattack on logistics giant CEVA delivers customer data into the wrong hands About Apple threat notifications and protecting against mercenary spyware If Apple sends you a push notification alerting you to a spyware attack, take it seriously AI isn’t changing how companies work. It’s changing what a company is Swarms of OpenAI systems set up their own chatrooms to discuss and carry out hacks, company reveals Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection Concept Drift Detection and Adaptive Retraining of Malware Classification Models A Comparison of Malware Image Transformations Using Grad-CAM and Hybrid Learning Models C-GUARD: Context-Adaptive Conformal Gating for Improving Robustness Against Evasive Windows PE Malware An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak." A security researcher who uses the "Nightmare Eclipse" handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. "Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day. "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible." Nightmare Eclipse described ShieldBreak as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June, and shared a ShieldBreak proof-of-concept (PoC) exploit that local attackers with limited permissions can use to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
Confirm this action.
Leaving now will discard your changes.