Microsoft issued a warning of potential legal action, yet this researcher has still released a new Windows vulnerability.
Digital Trends may earn a commission from purchases made through links on our site. Why trust us?
Windows Defender was intended to provide protection, but at present, it's become the issue.
Microsoft's legal threats haven’t deterred security researcher Nightmare Eclipse. Just weeks after the company hinted it might target researchers disclosing undisclosed vulnerabilities outside its official channels, Nightmare Eclipse unveiled a new vulnerability in Windows, and it’s a serious one.
What does ShieldBreak do?
The newly identified bug, named ShieldBreak, affects Windows Defender, the integrated anti-malware system included with every Windows installation. When successfully exploited, it allows an attacker to escalate privileges from a low-level user account to complete system access, effectively giving away control of your entire device.
Nightmare Eclipse
Nightmare Eclipse made the proof of concept available as a downloadable application for Windows, meaning the exploit requires someone to run it for the attack to work. The researcher states ShieldBreak impacts Windows 10, Windows 11, and Windows Server 2025. Security researcher Will Dormann has confirmed the bug's functionality but pointed out that Windows Defender must be enabled for the exploit to be successful.
This isn't the first time Nightmare Eclipse has faced off against Microsoft. ShieldBreak allegedly builds on a prior exploit known as RoguePlanet. Although Microsoft addressed that issue, the researcher argues the fix wasn't sufficient, and ShieldBreak circumvents it entirely.
Why is Microsoft in the spotlight again?
As reported by TechCrunch, this saga forms part of a prolonged conflict between Nightmare Eclipse and Microsoft regarding the company's approach to bug reporting. The researcher has accused Microsoft of mishandling earlier disclosures, resulting in several bugs being made public instead of being patched quietly.
In May, Microsoft exacerbated the situation by threatening legal action against researchers who disclose zero-days outside its defined rules. The security community reacted strongly, prompting Microsoft to soften its position on social media, although the original blog post remains published.
Currently, Microsoft states it is “aware of the reported vulnerability and is actively investigating.” There is no patch available yet, so if you use Windows, it’s important to stay informed about this issue.
Rachit Agarwal is an experienced tech journalist with over a decade of experience covering consumer technology.
Comu’s compact AI recorder can transform your meetings into slides, emails, and action plans.
The Comu Action Pro can record for up to 70 hours and supports more than 113 languages. AI voice recorders capable of capturing meetings, transcribing discussions, and generating summaries are increasingly prevalent. For instance, Flowtica's Scribe integrates these functions into a pen suited for handwritten notes. Comu, formerly Comulytic, has advanced this idea with the Action Pro, a pocket-sized AI recorder that can convert recorded dialogues into editable presentations, follow-up emails, meeting briefs, documents, and action plans. The device features a specific AI button that enables users to request these materials via voice commands.
Read more
Microsoft urges users to move away from SMS passwords as AI complicates phishing prevention.
Microsoft has issued a significant warning to IT administrators, urging an end to the use of SMS and voice-based authentication due to AI-driven phishing risks.
Why is Microsoft eliminating SMS authentication?
Read more
Twitch is utilizing your streams to train Amazon’s AI, and you are automatically opted in.
It turns out your favorite streamer might unknowingly be contributing to the training of Amazon's AI.
Twitch has quietly begun using your streams, VODs, and clips in Amazon's AI training process, with the opt-out feature buried so deep in the settings that the majority of users are unlikely to find it. As noted by Kotaku, streaming journalist Zach Bussey discovered a new toggle in Twitch's account settings on August 12, allowing users to prevent their content from being used to train Amazon's generative AI tools. The screenshot circulated quickly, along with a direct link to the specific settings page, mainly because Twitch didn’t announce this change initially.
Read more
Other articles
Microsoft issued a warning of potential legal action, yet this researcher has still released a new Windows vulnerability.
A researcher targeted by Microsoft with potential legal action has unveiled a new zero-day vulnerability in Windows named ShieldBreak, and it remains unpatched.
