Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users
It's the tenth zero-day the disgruntled researcher has disclosed
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu. (Image credit: Shutterstock)
Nightmare Eclipse discloses Shield Break, a new Windows privilege‑escalation zero‑day
Flaw bypasses a recent patch and works on fully updated Windows 11 systems
Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched
Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.
The newest flaw is called Shield Break, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches.
“The Po C was tested in the latest version of windows 11 25h 2 (+Canary channel) and windows server 2025, the Po C also have a 100% success rate,” Nightmare Eclipse said on their Git Hub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to Shield Break as well.”
The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called Rogue Planet.
“Microsoft has failed to properly patch the Rogue Planet vulnerability CVE-2026-50656, this Po C demonstrates a full patch bypass,” the Git Hub read entry.
Microsoft nemesis returns with another zero-day Po C — but is 'Legacy Hive' as nasty as expected?
This Microsoft Defender zero-day could give hackers unprecedented access to your system
Chaotic Eclipse strikes again with another worrying Windows security flaw
Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated vulnerability disclosure”.
In response to an enquiry by The Register, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."
"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."
Together with Shield Break, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated Blue Hammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed Blue Hammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure.
Just before publishing the work, they said “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”
Microsoft says it's hard at work on a patch for this worrying Defender zero-day
Microsoft breaks Patch Tuesday record with fixes for over 200 security flaws
Microsoft just released its biggest Patch Tuesday ever
At first, Microsoft took a tough stance, calling the public release “never justifiable” and even warning that it might pursue legal cases against people who put customers at risk.
The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”
In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released Red Sun and Un Defend (both targeting Defender), Yellow Key (a Bit Locker bypass), Green Plasma (a CTFMON-based privilege-escalation flaw), Mini Plasma (a regression of a vulnerability Microsoft had originally fixed in 2020), Rogue Planet (another Defender privilege-escalation bug), Great XML (a Bit Locker/Windows Recovery Environment bypass), Legacy Hive (a Windows User Profile Service privilege-escalation flaw), and now Shield Break.
Blue Hammer was fixed in April, Red Sun and Un Defend in May, and Yellow Key, Green Plasma, and Mini Plasma, in June. Rogue Planet was patched in July, while Legacy Hive, Great XML, and Shield Break, remain unpatched.
It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For Green Plasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components.
Shield Break, however, seems to be more dangerous in that respect. Speaking to The Register, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication.
He also said that while Shield Break was described as a bypass for the Rogue Planet fix, the two flaws actually operated quite differently.
“Rogue Planet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “Shield Break user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”
No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well.
➡️ Read our full guide to the best antivirus
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with Life Lock
- Best for mobile: Mc Afee Mobile Security
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Fans believe they've solved the secret name of The Elder Scrolls 6, and the clue might have been hidden in Starfield the whole time
Scientists are developing a ‘magnetoelastic’ tent that makes its own electricity like a wind turbine — but don’t expect to be able to take one to Glastonbury next year
Android users targeted by new Wind Relay malware which can clone contactless cards in just 13 minutes
New leak claims the first special edition Nintendo Switch 2 will be released to celebrate The Legend of Zelda's 40th anniversary — and yes, there are pictures
I shot the Perseid meteor shower after the eclipse with my Pixel and a pro Nikon camera — here’s which one I’d recommend for the spectacular celestial show tonight
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



