A security researcher has publicly released details of a new Windows vulnerability that grants hackers full system access, defying a legal warning from Microsoft issued weeks earlier. The exploit, dubbed ShieldBreak, was published on August 12, 2026, by researcher Nightmare Eclipse.
ShieldBreak exploits a flaw in Windows Defender, Microsoft’s built-in anti-malware engine, allowing an attacker to escalate from a low-level user account to complete control of a device and its data. The vulnerability affects Windows 10, Windows 11 — including the latest 25H2 version — and Windows Server 2025. Nightmare Eclipse published a proof-of-concept exploit as a Windows app, meaning a user must run the app for the attack to succeed. Independent security researcher Will Dormann verified the bug works, confirming that Windows Defender must be enabled for the exploit to function.
ShieldBreak builds on an earlier Nightmare Eclipse exploit called RoguePlanet, for which Microsoft issued a patch. The researcher implied that patch was insufficient, and that ShieldBreak represents a full bypass of Microsoft’s earlier fix. Microsoft has not released a patch for ShieldBreak, and a company spokesperson did not respond to a request for comment.
The disclosure is the latest episode in an ongoing dispute between Nightmare Eclipse and Microsoft. The researcher has claimed Microsoft mishandled their bug reports, leaving public disclosure as the only recourse. Several earlier Windows bugs released by Nightmare Eclipse were subsequently exploited in real-world attacks against organizations.
In May, Microsoft published a blog post threatening legal action against researchers who release zero-days outside its disclosure policies. The move drew significant criticism from the security community, and Microsoft later walked back the comments on social media, though its original post remains unchanged.
With no patch available, Windows users running Defender on affected versions remain exposed. The release arrived one day after Microsoft’s August Patch Tuesday update, which addressed roughly 500 bugs — a volume the company attributed in part to its growing use of AI to identify security flaws.
Source: TechCrunch