ELSEIF
Your brief EB
432 stories from 95 feeds 252 clusters Refreshed 6 minutes ago next pull 17:36

SECURITY Signal 421

Security researcher publishes Windows zero-day ShieldBreak despite Microsoft legal threat

Security researcher Nightmare Eclipse publicly disclosed a new Windows zero-day called ShieldBreak that allows privilege escalation via Windows Defender, continuing their release of unpatched vulnerabilities after Microsoft threatened legal action against such disclosures.

WHY IT MATTERS

ShieldBreak affects Windows 10, Windows 11 including version 25H2, and Windows Server 2025, and requires only that Windows Defender be enabled and a user execute the proof-of-concept app. The disclosure highlights an ongoing conflict between security researchers and Microsoft over bug handling, where previously released zero-days by the same researcher were later exploited in real-world attacks.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

ShieldBreak exploits a flaw in Windows Defender to escalate privileges from a low-level user to full system access, and a proof-of-concept exploit has been published as a Windows app.

02

The vulnerability is a full bypass of an earlier patch for a bug called RoguePlanet, indicating Microsoft's original fix was insufficient.

03

Microsoft has not yet released a patch for ShieldBreak, and the disclosure comes a day after the company's monthly Patch Tuesday release.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
TechCrunch After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug Open ↗