logo

Serial Microsoft 0-day hunter drops yet another Defender exploit

ID: 126bb29d-c97d-50ae-8980-9e22f28f5776

STIX ID: report--126bb29d-c97d-50ae-8980-9e22f28f5776

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-09-09

Date Updated: 2026-09-10

...
...

Nightmare Eclipse (MSNightmare) released a public proof-of-concept called ShieldCrash that allegedly bypasses recent Microsoft Defender patches and allows arbitrary file reads as SYSTEM on fully patched Windows 10, Windows 11, and Windows Server systems; the release is described as a bypass of prior Defender zero-days (ShieldBreak and RoguePlanet) and was published shortly after Patch Tuesday, with Microsoft not yet responding or issuing a fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.