Vulnerability Disclosure - 6 min read - 13 August 2026

Microsoft threatened legal action against researchers who go public in May. One of them just published his ninth zero-day.

A day after August's Patch Tuesday, the researcher known as Nightmare Eclipse released ShieldBreak - a working bypass of the fix Microsoft shipped in July for a Defender privilege-escalation flaw he disclosed in June. It's his ninth Windows zero-day since April, and it lands three months after Microsoft published a warning about researchers exactly like him.

In May 2026, Microsoft published a blog post warning that it would consider legal action against security researchers who disclose zero-day vulnerabilities outside its official channels. A spokesperson later walked the comments back on social media, though, as TechCrunch reported, the original post remains published and unchanged. On 12 August, one day after Microsoft's August Patch Tuesday, the researcher who goes by Nightmare Eclipse published ShieldBreak: a full bypass of the patch Microsoft shipped in July for CVE-2026-50656, a Defender privilege-escalation flaw he had disclosed in June under the name RoguePlanet. Whatever effect Microsoft intended the May warning to have, it did not include this researcher deciding to stop.

The bug the patch was supposed to have closed

RoguePlanet exploited a filesystem race condition and improper link resolution inside mpengine.dll, Defender's malware protection engine, to escalate a low-privilege process to NT AUTHORITY\SYSTEM. Microsoft's July fix, shipped as engine version 1.1.26060.3008, closed that specific race condition. According to BleepingComputer's write-up, ShieldBreak doesn't reopen it - it uses a different mechanism entirely, a user-mode callback hook that alters file contents mid-scan during Defender's cloud-hydration process via the Cloud Filter API. Same destination, SYSTEM-level access, reached by a route the July patch was never built to block. In testing, it hits 100% success against Windows 11 25H2, Windows 11 Canary and Windows Server 2025; Windows 10 and other Server editions weren't part of the published testing but aren't confirmed safe either. There is no fix for ShieldBreak available at time of writing.

This isn't his first Defender bypass, and that's the actual story

ShieldBreak is the ninth zero-day this researcher has published since April 2026, following LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and UnDefend - a run that spans Defender, BitLocker and other core Windows components, and one that we've already covered once on this site when BlueHammer turned out to be the flaw ransomware crews were using once they'd gained a foothold. A pattern of nine disclosures from one source in four months is unusual regardless of motive, but the researcher's own stated reason is specific: that Microsoft mishandled his prior bug reports and left him with no route to a fix other than making the flaw public himself. Microsoft's response to ShieldBreak, relayed to TechCrunch, was that it is "aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims" - notably not a denial that the bypass works, and not yet an account of what happened to the reports that preceded it.

A disclosure policy that produces the outcome it was meant to prevent

The May legal-action post was framed as a deterrent. What it's coincided with instead is a researcher escalating from private reports to public zero-days at a rate of roughly two a month, each one landing with full technical detail and no coordinated patch window. Whether Microsoft's post caused that shift or simply failed to stop a trajectory that was already under way, the practical result for defenders is the same either way: a vendor's own disclosure posture is now a variable in how much warning you get before a bypass lands, alongside the technical severity of the bug itself. A hard line on unauthorised disclosure only works as intended if it also fixes whatever made the researcher go around the official channel in the first place - otherwise it's a policy that changes the tone of the next disclosure, not whether one happens.

  • Assume Windows 11 25H2, Windows 11 Canary and Windows Server 2025 running Defender are exposed to SYSTEM-level compromise via ShieldBreak until Microsoft ships a fix; there is no patch to apply yet.
  • Deploy the available compensating controls now rather than waiting for a fix: enable Tamper Protection, restrict local admin rights, apply Attack Surface Reduction rules, and monitor MsMPEng.exe for unexpected child processes or token duplication.
  • Track this researcher's disclosure history, not just this one CVE - nine zero-days in four months from one source is itself a signal worth feeding into your threat model, independent of any single bug's severity.
  • Don't treat "patched" as a closed status for Defender privilege-escalation flaws from this research lineage; RoguePlanet shows a shipped fix can be bypassed by a different technique against the same underlying goal within weeks.

A patch that closes one route to SYSTEM access doesn't guarantee the researcher who found it has run out of others. If you need help building compensating controls around an unpatched Windows privilege-escalation chain, or want a second opinion on your Defender hardening posture, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources