Monday, September 28, 2026Verified technology journalism

Security researcher publishes unpatched Windows zero-day after Microsoft threatened legal action over prior disclosures

A researcher operating under the name Nightmare Eclipse has published a working exploit for a new Windows zero-day dubbed ShieldBreak, which abuses Windows Defender to grant hackers full system-level access across Windows 10, Windows 11, and Windows Server 2025. Microsoft has not released a patch. The disclosure arrives weeks after Microsoft publicly threatened legal action against researchers who release zero-days outside its disclosure policies, then partially retracted the warning on social media while leaving the original threat post unchanged. Security researcher Will Dormann independently verified that the exploit works. The standoff is the latest escalation in a long-running dispute between the researcher, who says Microsoft mishandled their earlier bug reports, and the software giant.

Security researcher publishes unpatched Windows zero-day after Microsoft threatened legal action over prior disclosures

Microsoft Threatened Legal Action Against a Security Researcher. The Response Was a Ninth Unpatched Zero-Day.

A security researcher has published a working exploit for an unpatched Windows zero-day that turns Windows Defender into an attack tool, weeks after Microsoft publicly threatened legal action against researchers who disclose flaws outside its policies. The exploit, dubbed ShieldBreak, was independently verified by security researcher Will Dormann. Microsoft has released no patch. 1

ShieldBreak is a full bypass of a patch Microsoft issued for a prior Nightmare Eclipse disclosure called RoguePlanet (CVE-2026-50656, CVSS 7.8). It escalates an attacker from a low-privilege local user to SYSTEM-level control across Windows 10, Windows 11 including the 25H2 release, and Windows Server 2025, with a reported 100 percent success rate on tested machines. Windows Defender must be enabled for the exploit to function, meaning the security tool built to stop attacks is itself the attack vector. 2

This is the ninth Windows zero-day Nightmare Eclipse has disclosed since April 2026, in what security researchers describe as an escalating retaliatory campaign against Microsoft over its handling of bug reports. 3 Eight of those nine have since been patched. But ShieldBreak proves the RoguePlanet fix was incomplete, and ShieldBreak itself remains open with verified exploit code publicly available. Three of the earlier bugs were exploited in real-world attacks before Microsoft shipped fixes. 4

A threat retracted on social media, left standing on the blog

On May 27, 2026, the Microsoft Security Response Center published a post calling uncoordinated disclosures "never justifiable," naming six recently leaked flaws, and stating that its Digital Crimes Unit "will continue bringing cases" against those who enable them. 5

Five days later, on June 1, Microsoft posted a clarification on X saying it had "no intention to pursue action against individuals conducting or publishing their security research." That clarification appeared only on social media. The original MSRC blog post, with its enforcement language, remains published and unchanged. 5

Between the original post and the walkback, Microsoft had already taken enforcement actions against the researcher. GitHub terminated the Nightmare Eclipse account on May 23, wiping six exploit repositories. GitLab suspended a mirrored account on May 26. Microsoft referred the matter to law enforcement on May 28. 4 The researcher also says Microsoft revoked access to its bug-reporting portal and refused to pay bounties on confirmed findings. 6 Microsoft did not credit the researcher for BlueHammer, the first disclosure, assigning the CVE credit to two other researchers instead. 3

The sequence produced a structural problem. By revoking portal access, banning code repositories, and involving law enforcement, Microsoft eliminated every private channel through which the researcher could report a vulnerability quietly. The researcher said as much: once code is public, "Microsoft cannot unwrite my code." 4 Further bans, the researcher wrote, no longer matter. 4

Nine disclosures, timed to the patch calendar

The full disclosure record, assembled across five sources, shows that later releases consistently land within hours of Microsoft's monthly Patch Tuesday, maximizing the window before the next patch cycle can respond.

  • BlueHammer (CVE-2026-33825): first disclosure April 3. Patched April 14. Exploited in the wild. 4
  • RedSun (CVE-2026-41091): patched out-of-band May 21. Exploited in the wild. Added to CISA's Known Exploited Vulnerabilities catalog. 4
  • UnDefend (CVE-2026-45498): patched out-of-band May 21. Exploited in the wild. Added to CISA's KEV catalog. 4
  • YellowKey (CVE-2026-45585): patched June 9. 4
  • GreenPlasma (CVE-2026-45586): patched June 9. 4
  • MiniPlasma (CVE-2020-17103): patched June 9. 4
  • RoguePlanet (CVE-2026-50656): disclosed June 10, the day after Patch Tuesday. Patched roughly one month later. Now bypassed by ShieldBreak. 2
  • LegacyHive (CVE-2026-62832): disclosed in July. Patched August 11 Patch Tuesday. 2
  • ShieldBreak: disclosed August 12, the day after Patch Tuesday. No patch. 1

Of these nine disclosures, eight have received patches. ShieldBreak demonstrates that the RoguePlanet fix was incomplete, and ShieldBreak itself has no fix. Three bugs, confirmed by Huntress researchers who documented intrusion chains using BlueHammer, RedSun, and UnDefend, were exploited in real attacks before patches arrived. 4 The August Patch Tuesday that preceded ShieldBreak's release shipped 421 patches, 236 of them for Windows. 2

The breakdown here is structural, not personal. Coordinated vulnerability disclosure assumes both sides gain from cooperation: the researcher gets acknowledgment and compensation, the vendor gets time to fix the bug before exploit code circulates. Microsoft revoked the portal access, withheld the bounties, denied the CVE credit, banned the repositories, and involved law enforcement. Each action was defensible in isolation. Together, they removed every incentive a researcher has to report privately. ShieldBreak is what the ninth bug looks like when that incentive structure is gone: published immediately, verified by a third party, no patch available, timed to land the day after Patch Tuesday. The researcher who knows Windows internals best now has every reason to publish the tenth the same way.

References

1.TechCrunch, August 12, 2026techcrunch.com ↗
2.The Hacker News, August 12, 2026thehackernews.com ↗
3.Barracuda Networks, May 19, 2026blog.barracuda.com ↗
5.The Cyber Signal, May 28, 2026thecybersignal.com ↗
6.The Register, June 10, 2026theregister.com ↗

Cite this story

ProvenBrief (2026). "Security researcher publishes unpatched Windows zero-day after Microsoft threatened legal action over prior disclosures." ProvenBrief. https://provenbrief.com/story/security-researcher-publishes-unpatched-windows-zero-day-after-microsoft-threate

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified41 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.