Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities Dark Reading

Nightmare-Eclipse Strikes Again with 'ShieldCrash' Windows Exploit

The ShieldCrash exploit is a patch bypass for CVE-2026-69414 (ShieldBreak), a privilege escalation flaw in the Microsoft Malware Protection Engine that allows arbitrary file read as SYSTEM. The CVE has a CVSS 3.1 score of 7.8 (High) and affects an unspecified version range of the Microsoft Malware Protection Engine.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS CYBER RISK CYBERATTACKS & DATA BREACHES CYBERSECURITY OPERATIONS NEWS Nightmare-Eclipse Strikes Again with 'ShieldCrash' Windows Exploit The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender. Elizabeth Montalbano,Contributing Writer September 10, 2026 4 Min Read SOURCE: ANDRIY POPOV VIA ALAMY STOCK PHOTO On the heels of a record-breaking Patch Tuesday, the disgruntled security researcher known as Nightmare-Eclipse dropped yet another Windows zero-day exploit, which enables privilege escalation and bypasses the fix for a previous Windows exploit released last month. The latest from the researcher — who also goes by Chaotic Eclipse, MSNightmare, and their X handle, Infinite Nightmare — is the "ShieldCrash" exploit, which they claim is a patch bypass for CVE-2026-69414, or "ShieldBreak." ShieldBreak is a privilege escalation flaw in the Microsoft Malware Protection Engine of Windows Defender. Nightmare-Eclipse released the ShieldBreak exploit on August's Patch Tuesday, one in a series of exploits for Windows flaws released monthly by the researcher since April. Microsoft has since patched the flaw, but the researcher claims it was not done properly. "Under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak," they wrote in the "README" file of ShieldCrash's extensive GitHub post. "While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited." Related:Patch Tuesday Sets Another Record With 974 CVEs The proof-of-concept (PoC) exploit released on GitHub "demonstrates an arbitrary file read as SYSTEM with September 2026" and affects all supported Windows versions, according to the exploit's GitHub description. Dark Reading contacted Microsoft dfor comment on the ShieldBreak exploit and its validity, but the company did not respond at press time. Ongoing Feud with Microsoft Nightmare Eclipse appears to show no signs of dropping their vendetta against Microsoft, which started in April with the release of BlueHammer zero-day exploit and stemmed from a disagreement over bug reports to the software giant. At one point Microsoft appeared to threaten legal action against the researcher, a stance that largely was met with disdain by the security community. Nightmare-Eclipse apparently remains undaunted, and has continued dropping fresh zero-day exploits on Microsoft's monthly Patch Tuesdays, which could give attackers weeks to weaponize the flaws unless the company releases out-of-band patches. "I absolutely hate it when you have two groups of people beefing with each other when they should be working together," John Strand, owner of Black Hills Information Security, tells Dark Reading. "On one side, this just feels petty on Microsoft's part, and it feels petty on the part of MSNightmare. It's sad, because we should be working together rather than dealing with egos." Related:AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready? Nightmare-Eclipse's exploits including RoguePlanet, YellowKey, GreenPlasma, MiniPlasma, and others. The researcher often will follow up Microsoft's patch for their previous exploit with yet another exploit that cracks the fix. For example, ShieldBreak was a bypass for Microsoft's patches against RoguePlanet, a race condition bug released on June 2026 Patch Tuesday. This week's exploit, ShieldCrash, is yet another example, and it appears to expose a recurring weakness in how this attack path has been remediated by Microsoft, says Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar. "When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch," he tells Dark Reading. However, having examined Nightmare-Eclipse's latest exploit, Seker says "it does not yet provide an attacker with a full SYSTEM shell or arbitrary write capability," but it does allow an adversary to perform an arbitrary file read under the SYSTEM security context on fully patched Windows systems. Take ShieldCrash Seriously Appearing to strike back against this assessment, Nightmare-Eclipse wrote on Wednesday in a post on X that the exploit is indeed "a full privilege escalation, not just an arbitrary file read," adding, "I'm curious if anyone is able to make a full exploit out of this before I do." Related:SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE Even if the exploit does only allow the arbitrary file read, as Seker claims, it is still a threat, he notes. "That could expose highly sensitive files that an ordinary user cannot access, including configuration data, credentials or other secrets," Seker says. This privileged file disclosure, in turn, "can become an important component of a larger attack chain." While typically organizations feel safe after they've applied patches, Nightmare-Eclipse and their ongoing exploit efforts consistently aim to undermine this trust, especially for Windows users. However, organizations shouldn't just disable Windows Defender because they worry about its security, Seker says. Instead, security teams should closely monitor Microsoft's guidance and Defender intelligence updates, ensure tamper protection is enabled, restrict local execution and administrative access, and hunt for suspicious processes interacting with protected files through Defender-related mechanisms, Seker advises. Also, because there is now public exploit code, defenders should expect that attackers will use it to gain access for malicious activities such as credential theft, persistence or full privilege escalation, Seker says. "Microsoft should also assess the complete vulnerability class and related code paths," he adds, "not only the specific condition demonstrated by this latest proof of concept." About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cybersecurity Outlook 2027 Threat Exposure Analytics: Measuring and Communicating Security Risk Benchmark Scores Are a False Flag Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach More Webinars You May Also Like VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 VULNERABILITIES & THREATS 'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails by Nate Nelson SEP 19, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article