A researcher known as Nightmare Eclipse published ShieldBreak on August 12, a working Microsoft Defender zero-day that defeats the July patch for RoguePlanet (CVE-2026-50656) and hands a normal user SYSTEM privileges. It was tested at a 100 percent success rate on fully updated Windows 11 25H2 and Windows Server 2025. There is no CVE and no fix.

Read the full story: ShieldBreak Zero-Day Bypasses Microsoft's Defender Patch →

Transcript

Microsoft patched this bug in July. On August twelfth it came back. A researcher going by Nightmare Eclipse published a working Windows Defender exploit called ShieldBreak. It takes a normal user account all the way to SYSTEM. Full control of the machine. And it works on Windows eleven twenty five H two and Server twenty twenty five, fully patched, at a hundred percent success rate. Here's the part that matters. This isn't a new bug. It's a bypass. Microsoft looked at the original flaw, decided it was a virtual disk race, and fixed that. ShieldBreak walks in through cloud file hydration instead. Same ending, different door. There's no CVE for it. There's no patch. And this is the eighth zero day from the same researcher since April, after Microsoft threatened to take legal action against them.