READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Researcher Publishes Unpatched Windows Defender Exploit After Microsoft Threatened Legal Action

Researcher Publishes Unpatched Windows Defender Exploit After Microsoft Threatened Legal Action
A researcher going by Nightmare Eclipse released a working zero-day exploit called ShieldBreak that abuses Windows Defender to hand attackers full system access, no patch exists yet. Microsoft threatened this same researcher with legal action in May over previous disclosures, then backed off the threat without pulling the blog post that made it.

A security researcher known online as Nightmare Eclipse has published full details and a working proof-of-concept for a new Windows vulnerability called ShieldBreak. The bug exploits a flaw in Windows Defender, Microsoft's built-in anti-malware engine, to let an attacker jump from a low-level user account to full system control.

According to Nightmare Eclipse's post, the exploit works on Windows 10, Windows 11 (including the current 25H2 release), and Windows Server 2025. It was packaged as a Windows app, meaning a target has to run the program for the attack to work. Security researcher Will Dormann independently verified the exploit functions as described, and confirmed Windows Defender has to be turned on for it to succeed, according to TechCrunch.

No patch exists for ShieldBreak. Microsoft did not respond to a request for comment from TechCrunch. Because Microsoft got zero advance notice, this qualifies as a true zero-day: the vulnerability is public before the company had any chance to fix it.

This isn't Nightmare Eclipse's first release

ShieldBreak builds directly on an earlier exploit from the same researcher called RoguePlanet. Microsoft did ship a patch for RoguePlanet. Nightmare Eclipse says that patch didn't actually close the hole, and that ShieldBreak is a full bypass of Microsoft's fix.

The researcher has published multiple Windows bugs over the past several months. In blog posts, Nightmare Eclipse has said Microsoft mishandled the bug reports and gave the researcher little choice but to go public. Some of the researcher's earlier disclosures were later used in real-world attacks against organizations, according to TechCrunch.

Microsoft threatened researchers, then backed off, without deleting the threat

In May, Microsoft published a blog post warning it would consider legal action against security researchers who release zero-day details outside the company's own disclosure process. That drew sharp pushback from the security research community. Multiple researchers said they'd had similar experiences dealing with Microsoft's bug-reporting pipeline.

Microsoft walked back the comments in a social media post, but the original blog post threatening legal action is still live and unchanged, according to TechCrunch. A company can say it didn't mean it while leaving the actual threat sitting on its own website.

The fair case for Microsoft's position

Coordinated disclosure exists for a reason. When a researcher reports a bug privately and gives a vendor time to patch it before going public, users are protected while a fix gets built. Public zero-days without a patch put every unpatched machine at immediate risk, including hospitals, small businesses, and regular consumers who have no idea Defender has a hole in it. Microsoft, or any software vendor, has a legitimate interest in encouraging researchers to report privately first. A company managing patches for over a billion devices has a real operational case for wanting an orderly disclosure timeline rather than researchers going public on their own schedule.

The problem is Microsoft's own credibility on this specific point. If a company wants researchers to trust its private disclosure process, threatening lawsuits against people who've said that process failed them is not how you build that trust. The security community's public rebuke in May wasn't fringe grumbling. It came from researchers who work with Microsoft regularly.

What's proven versus what's disputed

What's confirmed: the exploit works, per independent verification from Will Dormann. What's Nightmare Eclipse's claim, not independently established here: that Microsoft's handling of past bug reports was bad enough to justify skipping coordinated disclosure entirely, and that Microsoft's RoguePlanet patch was inadequate rather than simply incomplete against a new variant. Both are plausible reads of the same facts, and Microsoft hasn't offered its own account of the researcher interactions publicly.

ShieldBreak surfaced the day after Microsoft's monthly Patch Tuesday release, meaning the next scheduled fix is roughly a month out unless Microsoft issues an out-of-cycle emergency patch. Until then, every Windows 10, Windows 11 25H2, and Windows Server 2025 machine running Defender is sitting exposed to a publicly documented technique. Whether Microsoft ships an emergency patch, and whether it makes good on its May legal threat against the researcher who exposed it, are both open questions as of today.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchAfter Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug