Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin Is Down But Asset’s Role As Global Monetary Alternative Remains, Says Blackrock

    August 19, 2026

    Ukraine’s sacked defence minister Fedorov calls for wartime presidential elections

    August 19, 2026

    5 Things to Know About Mary Peltola, Democratic Senate Candidate in Alaska

    August 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin Is Down But Asset’s Role As Global Monetary Alternative Remains, Says Blackrock
    • Ukraine’s sacked defence minister Fedorov calls for wartime presidential elections
    • 5 Things to Know About Mary Peltola, Democratic Senate Candidate in Alaska
    • U.S. Cuts Back Military Drills With South Korea, as Trump Woos Kim Jong-un
    • Panel remarks about the European economy during a discussion on the global economic outlook at the World Economic Forum
    • Meta hooked children on Facebook and Instagram, US court hears
    • Microsoft working on Defender patch for ShieldBreak zero-day
    • Bitcoin As Digital Real Estate: An Excerpt From Leon Wankum’s Digital Real Estate
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft working on Defender patch for ShieldBreak zero-day

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 19, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named “ShieldBreak.”

    A security researcher who uses the “Nightmare Eclipse” handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates.

    ​”Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day.

    image

    “Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible.”

    Nightmare Eclipse described ShieldBreak as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June, and shared a ShieldBreak proof-of-concept (PoC) exploit that local attackers with limited permissions can use to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.

    “Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” Nightmare Eclipse said.

    “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”

    Vulnerability analyst Will Dormann confirmed last week that the ShieldBreak exploit works but added that Microsoft Defender must also be enabled for attackers to escalate privileges.

    ShieldBreak PoC exploit demo
    ShieldBreak PoC exploit demo (Nightmare Eclipse)

    Tracked as CVE-2026-69414 and waiting for a patch

    On Friday, three days after ShieldBreak was disclosed, Microsoft said it’s now tracking the flaw as CVE-2026-69414and confirmed it’s working on a patch, but has yet to acknowledge that Nightmare Eclipse found it.

    “Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘ShieldBreak,'” the company said. “We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.”

    Nightmare Eclipse publicly disclosed ShieldBreak without notice to Microsoft as part of an ongoing dispute with the company over its vulnerability disclosure and bug bounty practices.

    Days after the researcher published PoC exploits without prior notice, Microsoft responded with warnings of legal action against people engaging in “malicious activity causing real harm” to its customers, prompting many to believe that the company was directly threatening the security researcher.

    Since April, Nightmare Eclipse has disclosed multiple zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components, now known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.

    While the company fixed the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday and RoguePlanet in July, the other security flaws disclosed by Nightmare Eclipse remain zero-days and are still awaiting an official patch.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    defender Microsoft patch ShieldBreak working ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

    Philips and GE investigating Clop ransomware data theft claims

    Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

    Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

    Your Controls Block Known Attacks. What About the Behavior?

    Clop created custom web shell for Windchill data theft attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin Is Down But Asset’s Role As Global Monetary Alternative Remains, Says Blackrock

    August 19, 2026

    Ukraine’s sacked defence minister Fedorov calls for wartime presidential elections

    August 19, 2026

    5 Things to Know About Mary Peltola, Democratic Senate Candidate in Alaska

    August 19, 2026

    U.S. Cuts Back Military Drills With South Korea, as Trump Woos Kim Jong-un

    August 19, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin Is Down But Asset’s Role As Global Monetary Alternative Remains, Says Blackrock

    August 19, 2026

    Ukraine’s sacked defence minister Fedorov calls for wartime presidential elections

    August 19, 2026

    5 Things to Know About Mary Peltola, Democratic Senate Candidate in Alaska

    August 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.