Close Menu
NCIJ Network NCIJ Network
    What's Hot

    LNG-to-FSRU conversion widening Karpowership-backed Kinetics’ gas infrastructure fleet

    September 30, 2026

    California Regulators Did Little to Punish a Raw Milk Farm After Two Girls Got Sick — ProPublica

    September 30, 2026

    Prosecco pratfalls and coffee catastrophes: Neets are missing out on formative first-job experiences | Isabel Brooks

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • LNG-to-FSRU conversion widening Karpowership-backed Kinetics’ gas infrastructure fleet
    • California Regulators Did Little to Punish a Raw Milk Farm After Two Girls Got Sick — ProPublica
    • Prosecco pratfalls and coffee catastrophes: Neets are missing out on formative first-job experiences | Isabel Brooks
    • Peter Thiel said, ‘If you’re evil, you’re not bad.’ Here’s the context
    • ‘I wanted to live’: A Ukrainian orphan’s journey through Russian occupation | Russia-Ukraine war News
    • Europe’s energy security has a Black Sea opportunity – POLITICO
    • Mediation over Drumcree parade is ‘dead in the water’, say nationalists | Northern Ireland
    • Apple Pay finally launches in India after years on the sidelines
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak.

    The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet.

    RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions.

    Although it was first disclosed by the researcher in June 2026, a patch for the vulnerability was not released by Microsoft until almost a month later. The tech giant described it as a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”).

    Cybersecurity

    Soon after, Chaotic Eclipse said the “defense-in-depth updates” introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025. Microsoft told The Hacker News at the time that it’s aware of the report and is investigating.

    ShieldBreak, on the other hand, is assessed to be a full patch bypass for CVE-2026-50656, with the researcher claiming that “Microsoft has failed to properly patch the RoguePlanet vulnerability.”

    “The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate,” the researcher added. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”

    When contacted for comment, a Microsoft spokesperson shared the following statement with The Hacker News –

    Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public.

    Security researcher Kevin Beaumont, in a post on Mastodon, confirmed the exploit works on Windows 11, adding that the two exploits work differently.

    “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont noted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”

    Will Dormann, principal vulnerability analyst at Tharros, also validated ShieldBreak, stating Defender needs to be enabled for the exploit to work and that “my naive eyeballs fail to see the similarity” with RoguePlanet. Dormann explained the sequence of actions as follows –

    • Plant an EICAR file
    • Use Object Manager symlinks to control Defender’s scan path to system32.
    • During the scan, leverage CLFS to swap the identity file and hydration data to C:Windowssystem32phoneinfo.dll (which doesn’t exist by default in Windows)
    • Run the QueueReporting scheduled task, which runs wermgr.exe -upload as Run with highest privileges

    “In the wer.dll code, there is explicit code to load phoneinfo.dll,” the researcher said. “Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges. I don’t recall RoguePlanet doing anything with cloud providers, CLFS, hydration anything, phoneinfo.dll, and unlike RoguePlanet, ShieldBreak seems to require Defender to be active to work.”

    The development comes as the Windows maker shipped patches for 421 security flaws, including 236 flaws in Windows. One of the patches involves CVE-2026-62832 (CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name LegacyHive.

    “Improper link resolution before file access (‘link following’) in Windows User Profile Service allows an authorized attacker to elevate privileges locally,” Microsoft said.

    Cybersecurity

    “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required.”

    Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (CVE-2026-72971, CVSS score: 5.5).

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by August 25, 2026.

    (The story was updated after publication on August 13, 2026, to include a response from Microsoft and additional insights related to the flaw.)

    access Bypass claims defender Microsoft patch PoC ShieldBreak System ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters Defiant After FBI Calls on Members to Come Forward

    Can we jail a superintelligence?

    EU to offer single-market access to candidate countries – POLITICO

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    Pentagon Personnel Agency Data Breach Impacts 3 Million People

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    LNG-to-FSRU conversion widening Karpowership-backed Kinetics’ gas infrastructure fleet

    September 30, 2026

    California Regulators Did Little to Punish a Raw Milk Farm After Two Girls Got Sick — ProPublica

    September 30, 2026

    Prosecco pratfalls and coffee catastrophes: Neets are missing out on formative first-job experiences | Isabel Brooks

    September 30, 2026

    Peter Thiel said, ‘If you’re evil, you’re not bad.’ Here’s the context

    September 30, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    LNG-to-FSRU conversion widening Karpowership-backed Kinetics’ gas infrastructure fleet

    September 30, 2026

    California Regulators Did Little to Punish a Raw Milk Farm After Two Girls Got Sick — ProPublica

    September 30, 2026

    Prosecco pratfalls and coffee catastrophes: Neets are missing out on formative first-job experiences | Isabel Brooks

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.