Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day vulnerability

The prolific and controversial safety researcher often known as Nightmare-Eclipse (additionally tracked underneath the alias Chaotic Eclipse) has launched a ninth Home windows zero-day exploit referred to as ShieldBreak, and this time the goal is Microsoft’s personal repair.

ShieldBreak demonstrates an entire bypass of the patch Microsoft shipped for RoguePlanet, the Home windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656, proving that the underlying weak spot within the Microsoft Malware Safety Engine was by no means totally closed.

RoguePlanet was initially disclosed as a race situation in mpengine.dll, the core scanning engine behind Home windows Defender, that permit an area attacker win a slim check-then-act timing window throughout a file scan and redirect it right into a command shell working as NT AUTHORITYSYSTEM.

Microsoft ultimately acknowledged the bug, rated it “Exploitation Extra Seemingly” with a CVSS rating of seven.8, and remediated it in Malware Safety Engine model 1.1.26060.3008 throughout its July 2026 patch cycle.

Nightmare-Eclipse Drops ShieldBreak 0-Day

In accordance with Nightmare-Eclipse, nevertheless, that remediation solely closed one slim path into the weak code, leaving the broader race situation exploitable by means of a distinct method.

ShieldBreak proves the purpose by registering a rogue cloud supplier, attaching it to a crafted placeholder file, and utilizing CLFS log manipulation alongside object supervisor symbolic hyperlinks to trick Defender’s scanning pipeline into locking a professional system file resembling phonefo.dll whereas a malicious substitute is swapped beneath it, finally spawning a SYSTEM-level shell.

ShieldBreak Windows Defender 0-day
ShieldBreak Home windows Defender 0-day

The published proof-of-concept has reportedly been validated against Windows 11 25H2, together with builds on the Canary channel, and Home windows Server 2025, with the writer claiming a 100% success price throughout these targets. Home windows 10 and its corresponding server editions are described as weak as nicely, although the present PoC doesn’t formally assist them.

That form of reliability is uncommon for exploits constructed round race situations, which usually require a number of makes an attempt to win the timing window, and it raises the stakes for enterprises nonetheless working Defender as their major endpoint protection on the most recent Home windows builds.

ShieldBreak shouldn’t be an remoted launch. It’s the ninth in a working sequence from Nightmare-Eclipse that started with BlueHammer and RedSun earlier in 2026 and has since expanded to incorporate UnDefend, GreenPlasma, YellowKey, MiniPlasma, RoguePlanet, GreatXML, and now ShieldBreak.

A number of of those exploits particularly goal Defender’s cloud file and remediation mechanisms, whereas others deal with silently degrading its signature updates with out triggering well being alerts.

The marketing campaign has already drawn platform-level penalties, with GitHub and GitLab suspending the researcher’s accounts and forcing code to be mirrored on different hosts like Gitea to maintain releases publicly accessible.

Since ShieldBreak targets a spot in an already-shipped patch somewhat than a brand-new bug class, organizations mustn’t assume that putting in the July 2026 Defender engine replace totally resolves their publicity.

Safety groups ought to monitor endpoint detection instruments for uncommon cloud-provider registrations, object supervisor namespace manipulation, and surprising CLFS log exercise, and may deal with any SYSTEM-level shell spawned exterior regular administrative workflows as a powerful indicator of compromise till Microsoft points a extra complete repair for the underlying Malware Safety Engine flaw.

[Live Webinar] Be part of Elastic & UnderDefense to learn the way small safety groups can unify AI visibility and agentic response into one working mannequin -> Register Now

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *