Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Rescued from traffickers, reintroduced orangutan becomes mother in the wild

    August 14, 2026

    Breakwater rehabilitation making headway for Portugal’s 1 MW wave energy project

    August 14, 2026

    Three firefighters and a child hospitalised in England as fires blaze in UK, Greece, France and Croatia – Europe live | Climate crisis

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Rescued from traffickers, reintroduced orangutan becomes mother in the wild
    • Breakwater rehabilitation making headway for Portugal’s 1 MW wave energy project
    • Three firefighters and a child hospitalised in England as fires blaze in UK, Greece, France and Croatia – Europe live | Climate crisis
    • Farage’s victory over Binface won’t silence his critics – POLITICO
    • Farage wins Clacton by-election but avoids result declaration
    • Trump declares 100 percent tariffs on many drones and all aircraft parts
    • Z.ai Ships GLM-5.3 Without Retraining the Base Model: Better at Complex Coding and Long-Horizon Tasks
    • AI ‘watermark removers’ flood the web. Almost none can prove they work.
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft patches LegacyHive Windows zero-day vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft has released security patches to address a Windows zero-day vulnerability known as “LegacyHive,” disclosed after the July 2026 Patch Tuesday.

    The security flaw was disclosed by a security researcher who uses the “Nightmare Eclipse” handle in protest of Microsoft’s bug bounty and vulnerability disclosure practices.

    Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service.

    image

    However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.

    “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.

    Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse’s exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.

    One day after the PoC was released, cybersecurity expert Kevin Beaumont also published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.

    Official LegacyHive patches available

    Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. However, it has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead tagging it as reported by an anonymous researcher.

    The company says that LegacyHive stems from improper link resolution before file access (‘link following’) in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges.

    “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive,” Microsoft says. “Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required.”

    ACROS Security, the company behind the 0Patch cybersecurity platform, also released free unofficial LegacyHive patches on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.

    Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and other Windows components.

    Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, and the RoguePlanet vulnerability in July, but the other zero-days are still awaiting an official patch.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    LegacyHive Microsoft Patches Vulnerability Windows ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    Hackers breach govt webmail while running parallel crypto fraud

    Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Rescued from traffickers, reintroduced orangutan becomes mother in the wild

    August 14, 2026

    Breakwater rehabilitation making headway for Portugal’s 1 MW wave energy project

    August 14, 2026

    Three firefighters and a child hospitalised in England as fires blaze in UK, Greece, France and Croatia – Europe live | Climate crisis

    August 14, 2026

    Farage’s victory over Binface won’t silence his critics – POLITICO

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Rescued from traffickers, reintroduced orangutan becomes mother in the wild

    August 14, 2026

    Breakwater rehabilitation making headway for Portugal’s 1 MW wave energy project

    August 14, 2026

    Three firefighters and a child hospitalised in England as fires blaze in UK, Greece, France and Croatia – Europe live | Climate crisis

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.