CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs Aug 12, 2026

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access - The Hacker News

The Hacker News Archived Aug 12, 2026 ✓ Full text saved

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The Hacker News

Full text archived locally
✦ AI Summary · Claude Sonnet


    ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access Ravie LakshmananAug 12, 2026Zero-Day / Vulnerability The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions. Although it was first disclosed by the researcher in June 2026, a patch for the vulnerability was not released by Microsoft until almost a month later. The tech giant described it as a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"). Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025. Microsoft told The Hacker News at the time that it's aware of the report and is investigating. ShieldBreak, on the other hand, is assessed to be a full patch bypass for CVE-2026-50656, with the researcher claiming that "Microsoft has failed to properly patch the RoguePlanet vulnerability." "The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate," the researcher added. "Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well." The Hacker News has contacted Microsoft, and we will update the story if we hear back. The development comes as the Windows maker shipped patches for 421 security flaws, including 236 flaws in Windows. One of the patches involves CVE-2026-62832 (CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name LegacyHive. "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," Microsoft said. "An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required." Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (CVE-2026-72971, CVSS score: 5.5). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by August 25, 2026. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share SHARE  endpoint security, exploit, Microsoft, Patch Management, privilege escalation, Software Security, Vulnerability, Windows Security, Zero-Day ⚡ Top Stories This Week Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Get the 2026 CISO Benchmark Report Based on 600 Security Leaders Get the Checklist for Gaining Control of AI Use Across Your Organization Download the 5-Step Action Plan for AI-Speed Exploitation
    💬 Team Notes
    Article Info
    Source
    The Hacker News
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗