Overview
- The anonymous researcher known as Chaotic or Nightmare Eclipse published the ShieldBreak proof‑of‑concept on Wednesday and said it fully bypasses the July RoguePlanet fix.
- Multiple independent analysts reproduced the PoC and confirmed it grants SYSTEM privileges only when Microsoft Defender is enabled.
- Technical reviews show ShieldBreak manipulates Defender’s cloud‑hydration path and Cloud Filter API, uses a user‑mode callback to swap files into System32, and triggers a scheduled task to run attacker code as SYSTEM.
- Microsoft acknowledged the report, said it is actively investigating and reiterated support for coordinated disclosure, and has not announced a vendor patch specific to ShieldBreak.
- The release continues a months‑long run of public zero‑day disclosures by the same researcher, leaving system administrators to test updates, enable detections, or disable Defender where feasible to reduce short‑term exposure.