Researcher Publishes ShieldBreak Windows Zero-Day After Microsoft Dispute — What You Should Know

Researcher Publishes ShieldBreak Windows Zero-Day After Microsoft Dispute — What You Should Know

A new Windows zero-day called ShieldBreak can give attackers full access after a user runs a malicious app. Here’s what Windows users should know and do now to stay safer.

What Happened With the ShieldBreak Windows Zero-Day?

According to TechCrunch, security researcher Nightmare Eclipse published details of a new Windows zero-day on August 12, 2026.

A zero-day is a security flaw made public before the software maker has a fix ready.

The flaw, called ShieldBreak, affects Windows Defender, the security software built into Windows.

A successful attack can raise an attacker from limited access to full control of the device and its data.

Nightmare Eclipse also released a proof-of-concept Windows app showing how the bug can work. A proof of concept is a test that demonstrates a flaw.

The user must run the app for the published exploit to work.

Security researcher Will Dormann independently verified the bug and said Windows Defender must be enabled for the exploit to work.

As of TechCrunch’s August 12 report, Microsoft had not released a fix. The company said it was investigating the claims.

The disclosure came one day after Microsoft’s August Patch Tuesday, its monthly release of Windows security fixes.

It also followed months of conflict between Microsoft and Nightmare Eclipse over how the researcher disclosed earlier security bugs.

Microsoft had threatened legal action over zero-day disclosures outside its preferred process. The company later walked back those comments on social media.

If an attacker gains full access to a computer, personal files and account information stored on that device could also be at risk. Stolen information can later be reused in phishing emails, impersonation attempts, or other fraud.

It is also worth checking whether your information has already appeared in unrelated data breaches. Many people do not know their data was leaked until suspicious activity begins.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Which Windows Users Could Be Affected?

Nightmare Eclipse said ShieldBreak works on Windows 10, Windows 11, including version 25H2, and Windows Server 2025.

TechCrunch did not report how many Windows users may be affected or any confirmed ShieldBreak victims.

The report also did not describe confirmed data theft linked to this new flaw.

However, a successful attack could give an attacker full access to the device and its data.

TechCrunch did not report that ShieldBreak had already been used in real-world attacks when the article was published.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

How ShieldBreak Can Give Attackers Full Windows Access

ShieldBreak takes advantage of a flaw in Windows Defender, Microsoft’s built-in protection against harmful software.

The published exploit starts with limited user access and then raises those permissions to full device access.

That process is called privilege escalation, which means gaining more control over a computer than the original account should have.

Nightmare Eclipse said ShieldBreak builds on an earlier exploit called RoguePlanet.

Microsoft patched RoguePlanet, but the researcher said ShieldBreak can bypass that earlier fix.