Security researcher NightmareEclipse discloses a fresh Windows Defender flaw called ShieldBreak, claiming it can bypass patched vulnerabilities and grant full control over affected systems, intensifying tensions with Microsoft just before Patch Tuesday.
NightmareEclipse has released another Windows zero-day, this time a flaw he calls ShieldBreak, extending a public dispute with Microsoft over how quickly vulnerabilities in Windows Defender are fixed and how the company responds to independent researchers. The disclosure comes after Microsoft previously patched a separate Defender issue known as RoguePlanet, tracked as CVE-2026-50656, and the latest claim is that the earlier fix did not fully close the underlying weakness. According to the reporting, Microsoft is now investigating the new issue but has not endorsed NightmareEclipse’s account of how the bug works.
The researcher says ShieldBreak affects Windows Defender’s endpoint antivirus engine and can be used to bypass Microsoft’s prior patch. He has also published proof-of-concept code that, he claims, gives an attacker full control of a Windows machine. External researchers have said the flaw and the demonstration appear legitimate, although they have not necessarily agreed with his explanation of its relationship to RoguePlanet. Ars Technica reported in July that the earlier Defender weakness could let an attacker do serious damage even after Microsoft’s response, underlining how difficult these bugs can be to contain once public.
NightmareEclipse says his proof-of-concept was tested against current builds of Windows 11 25H2 and Windows Server 2025 and still worked, including on unsupported editions of Windows 10. That makes the disclosure more than a theoretical concern, particularly because it arrives just ahead of Patch Tuesday, leaving Microsoft little time to assess the claim before its next scheduled update cycle. PCWorld, TechRadar and Windows Central have all previously reported that Microsoft treated RoguePlanet as a serious Defender flaw that could allow attackers to reach SYSTEM-level privileges or full system access, reinforcing the importance of any alleged bypass of the original fix.
The dispute also reflects a wider breakdown in relations between the researcher and Microsoft. NightmareEclipse has previously accused the company of leaving deliberate weaknesses in Windows, while Microsoft has pushed back and at one point threatened legal action before retreating after criticism from the security community. Even so, the company has continued to investigate his disclosures, and the latest episode suggests that Defender remains a live target for both attackers and researchers looking for gaps in Microsoft’s defences.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





