Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
Brief
The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft’s own fix.
ShieldBreak demonstrates a complete bypass of the patch Microsoft shipped for RoguePlanet, the Windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656 , proving that the underlying weakness in the Microsoft Malware Protection Engine was never fully closed.
RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM.
Microsoft eventually acknowledged the bug, rated it “Exploitation More Likely” with a CVSS score of 7.
