Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology7 min read

Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users | TechRadar

It's the tenth zero-day the disgruntled researcher has disclosed Discover insights about microsoft's nemesis returns: nightmare eclipse is back with a new zero

TechnologyInnovationBest PracticesGuideTutorial
Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users | TechRadar
Listen to Article
0:00
0:00
0:00

Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users

It's the tenth zero-day the disgruntled researcher has disclosed

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu. (Image credit: Shutterstock)

Nightmare Eclipse discloses Shield Break, a new Windows privilege‑escalation zero‑day

Flaw bypasses a recent patch and works on fully updated Windows 11 systems

Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched

Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.

The newest flaw is called Shield Break, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches.

“The Po C was tested in the latest version of windows 11 25h 2 (+Canary channel) and windows server 2025, the Po C also have a 100% success rate,” Nightmare Eclipse said on their Git Hub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to Shield Break as well.”

The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called Rogue Planet.

“Microsoft has failed to properly patch the Rogue Planet vulnerability CVE-2026-50656, this Po C demonstrates a full patch bypass,” the Git Hub read entry.

Microsoft nemesis returns with another zero-day Po C — but is 'Legacy Hive' as nasty as expected?

This Microsoft Defender zero-day could give hackers unprecedented access to your system

Chaotic Eclipse strikes again with another worrying Windows security flaw

Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated vulnerability disclosure”.

In response to an enquiry by The Register, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."

"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."

Together with Shield Break, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated Blue Hammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed Blue Hammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure.

Just before publishing the work, they said “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”

Microsoft says it's hard at work on a patch for this worrying Defender zero-day

Microsoft breaks Patch Tuesday record with fixes for over 200 security flaws

Microsoft just released its biggest Patch Tuesday ever

At first, Microsoft took a tough stance, calling the public release “never justifiable” and even warning that it might pursue legal cases against people who put customers at risk.

The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”

In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released Red Sun and Un Defend (both targeting Defender), Yellow Key (a Bit Locker bypass), Green Plasma (a CTFMON-based privilege-escalation flaw), Mini Plasma (a regression of a vulnerability Microsoft had originally fixed in 2020), Rogue Planet (another Defender privilege-escalation bug), Great XML (a Bit Locker/Windows Recovery Environment bypass), Legacy Hive (a Windows User Profile Service privilege-escalation flaw), and now Shield Break.

Blue Hammer was fixed in April, Red Sun and Un Defend in May, and Yellow Key, Green Plasma, and Mini Plasma, in June. Rogue Planet was patched in July, while Legacy Hive, Great XML, and Shield Break, remain unpatched.

It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For Green Plasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components.

Shield Break, however, seems to be more dangerous in that respect. Speaking to The Register, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication.

He also said that while Shield Break was described as a bypass for the Rogue Planet fix, the two flaws actually operated quite differently.

“Rogue Planet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “Shield Break user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”

No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Fans believe they've solved the secret name of The Elder Scrolls 6, and the clue might have been hidden in Starfield the whole time

Scientists are developing a ‘magnetoelastic’ tent that makes its own electricity like a wind turbine — but don’t expect to be able to take one to Glastonbury next year

Android users targeted by new Wind Relay malware which can clone contactless cards in just 13 minutes

New leak claims the first special edition Nintendo Switch 2 will be released to celebrate The Legend of Zelda's 40th anniversary — and yes, there are pictures

I shot the Perseid meteor shower after the eclipse with my Pixel and a pro Nikon camera — here’s which one I’d recommend for the spectacular celestial show tonight

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.