Nightmare Eclipse
actor · actor:nightmare-eclipse single-source
Pseudonymous vulnerability researcher/broker persona (tracked under both names) publicly dropping Windows zero-day proof-of-concepts through 2026, the series includes BlueHammer, RedSun, UnDefend, YellowKey (BitLocker, later CVE-2026-45585), GreenPlasma (CTFMON LPE), MiniPlasma (cldflt.sys), GreatXML (BitLocker/WinRE) and RoguePlanet (Defender TOCTOU), and stating publicly that Microsoft will not engage with their reports.
Aliases: Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare
Action items (6)
Do-now tasks recorded on the entries about Nightmare Eclipse, newest first. Check the date before acting on an older one.
- Confirm every Windows endpoint reports Microsoft Malware Protection Engine 1.1.26080.3 or later; the engine version updates on its own cadence and is not covered by the OS patch level, so check it separately; 1.26070.7 is the last affected build.2026-08-12CVE-2026-50656 +1
- Hunt for C:\\Windows\\System32\\phoneinfo.dll across the Windows estate now; LevelBlue states the file is not expected to exist natively on supported Windows versions, so an instance on a supported build is either this chain or an unrelated planted DLL, and either warrants investigation.2026-08-12CVE-2026-50656 +1
- Confirm every CrowdStrike Falcon sensor and Gen Digital Avast install (including on unmanaged or contractor endpoints) is on the current release now that both vendors are reported to have remediated FalconFlank and PrettyPrague; until that is confirmed, treat any endpoint on an older build as still exposed and keep the "Microsoft Office File Suspicious Macro Removal Windows" Falcon prevention setting disabled as an interim control on unconfirmed hosts.2026-09-06CrowdStrike, Gen Digital and Kaspersky have all now…
- On WSUS-gated, air-gapped, offline or OT-adjacent Windows estates where Defender engine updates are deferred or pinned, verify the installed Malware Protection Engine build is ≥ 1.1.26060.3008 (e.g. via Get-MpComputerStatus AMEngineVersion) rather than assuming auto-update reached it.2026-07-09CVE-2026-50656
- Continue tracking the Nightmare Eclipse zero-day series via NCSC-CH's running advisory: RoguePlanet is now fixed, but the same researcher's series has previously dropped further unpatched Defender/Windows PoCs, so treat NCSC-CH's tracker as the authority for the current fix status of each.2026-07-09CVE-2026-50656
1 older action item
- Compensate for the unpatched Defender LPE (CVE-2026-50656) (§ 4). No patch exists, monitor for2026-06-19CVE-2026-50656
MsMpEng.exespawningcmd.exe/powershell.exeas SYSTEM (Sysmon EID 1 parent-image filter, WEL 4688) and constrain which low-privilege accounts can trigger on-demand scans.
Defender insights
What each entry about Nightmare Eclipse tells a defender to do, newest first.
Latest update · triage
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
exploits
attributed activity
Story timeline
Every entry that names Nightmare Eclipse, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-10-08BigDiskBuster: a roughly 300-line Windows proof of concept keeps Microsoft Defender from updating by claiming all free disk space, with no CVE and no patch
- 2026-09-06Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated
- 2026-08-12ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
- 2026-07-29LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems
- 2026-07-09CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series
- 2026-06-19Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch
- 2026-06-12"GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested
- 2026-06-11"RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch
- 2026-05-30Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop
- 2026-05-19Chaotic Eclipse Windows zero-days; MiniPlasma is third PoC in series; cldflt.sys CfAbortHydration path, claimed re-exploitable CVE-2020-17103 regression
- 2026-05-15Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed
Hunting pivots
ATT&CK techniques (18 across 7 tactics)
18 techniques observed across 6 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts
- ExecutionScheduled Task/Job: Scheduled Task · Native API · Hijack Execution Flow · Hijack Execution Flow: DLL
- PersistenceScheduled Task/Job: Scheduled Task · Valid Accounts · Modify Registry
- Privilege EscalationScheduled Task/Job: Scheduled Task · Exploitation for Privilege Escalation · Valid Accounts · Access Token Manipulation: Parent PID Spoofing · Abuse Elevation Control Mechanism · Abuse Elevation Control Mechanism: Bypass User Account Control
- StealthObfuscated Files or Information: Dynamic API Resolution · Masquerading: Match Legitimate Resource Name or Location · Indicator Removal: File Deletion · Valid Accounts · Access Token Manipulation: Parent PID Spoofing · Exploitation for Stealth · System Binary Proxy Execution · Hide Artifacts: Hidden Files and Directories · Hijack Execution Flow · Hijack Execution Flow: DLL
- Defense ImpairmentModify Registry · Disable or Modify Tools
- Credential AccessOS Credential Dumping: Security Account Manager
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1106Native API×2
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.
Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×2
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1068Exploitation for Privilege Escalation×5
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · 2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed · 2026-05-19/chaotic-eclipse-windows-zero-days-miniplasma-is-third-poc-in · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1134.004Access Token Manipulation: Parent PID Spoofing×1
Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the <code>CreateProcess</code> API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via <code>svchost.exe</code> or <code>consent.exe</code>) rather than the current user context.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗
T1548Abuse Elevation Control Mechanism×2
Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗
Stealth TA0005
T1027.007Obfuscated Files or Information: Dynamic API Resolution×1
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1070.004Indicator Removal: File Deletion×1
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1134.004Access Token Manipulation: Parent PID Spoofing×1
Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the <code>CreateProcess</code> API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via <code>svchost.exe</code> or <code>consent.exe</code>) rather than the current user context.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗
T1211Exploitation for Stealth×1
Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗
T1218System Binary Proxy Execution×1
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
T1564.001Hide Artifacts: Hidden Files and Directories×1
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls –a</code> for Linux and macOS).
Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · ATT&CK page ↗
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×2
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗
T1685Disable or Modify Tools×2
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-10-08/bigdiskbuster-defender-update-starvation-disk-exhaustion-poc · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗
Credential Access TA0006
T1003.002OS Credential Dumping: Security Account Manager×1
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.
Evidence: 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops · ATT&CK page ↗
Entries about Nightmare Eclipse (8)
Earlier coverage (5)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Nightmare Eclipse Windows zero-day series×6
- RoguePlanet×5
- Microsoft Defender Antivirus×3
- Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker×3
- LegacyHive×2
- Microsoft Windows×2
- Windows YellowKey BitLocker bypass via WinRE×2
- Avast Antivirus×1
Where this entity is cited
Source distribution
- msrc.microsoft.com5 (15%)
- levelblue.com4 (12%)
- bleepingcomputer.com3 (9%)
- thehackernews.com3 (9%)
- security-hub.ncsc.admin.ch2 (6%)
- securityweek.com2 (6%)
- theregister.com2 (6%)
- 0patch.com1 (3%)
- other11 (33%)
All cited sources (33)
- 0patch.com0patch (ACROS Security)https://0patch.com/blog/micropatches-available-for-legacyhive-windows-user-profile-service-elevation-of-p
- attack.mitre.orgT1542.001https://attack.mitre.org/techniques/T1542/001/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- bleepingcomputer.comBleepingComputer, 2026-05-13https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- cert.ssi.gouv.frCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1035/
- cyberkendra.comCyber Kendrahttps://www.cyberkendra.com/2026/08/shieldbreak-poc-bypasses-microsofts.html
- darkreading.comDark Readinghttps://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates
- github.comNightmare Eclipse, 2026-09-08https://github.com/MSNightmare/ShieldCrash
- heise.deheise Securityhttps://www.heise.de/en/news/Too-many-zero-days-Microsoft-threatens-legal-action-11310736.html
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/
- levelblue.comLevelBlue SpiderLabshttps://www.levelblue.com/blogs/spiderlabs-blog/cloud-sync-root-registrationshieldbreak-hunting-windows-defender-remediation-abuse-and-cloud-files-hijacking
- levelblue.comLevelBlue (Trustwave) SpiderLabshttps://www.levelblue.com/blogs/spiderlabs-blog/expanding-the-attack-surface-analyzing-nightmare-eclipses-latest-pocs
- levelblue.comLevelBlue SpiderLabshttps://www.levelblue.com/blogs/spiderlabs-blog/filling-the-well-nightmare-eclipses-bigdiskbuster-and-the-defender-update-that-never-lands
- levelblue.comLevelBlue SpiderLabshttps://www.levelblue.com/blogs/spiderlabs-blog/legacyhive-hunting-windows-profile-initialization-abuse-through-offline-registry-manipulation
- msrc.microsoft.comMSRC CVE-2026-45585, 2026-05-19https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585
- msrc.microsoft.comMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
- msrc.microsoft.comMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
- msrc.microsoft.comMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832
- msrc.microsoft.comMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
- rapid7.comRapid7https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/
- security-hub.ncsc.admin.chNCSC-CH Security Hub #12574, 2026-05-14https://security-hub.ncsc.admin.ch/#/posts/12574
- security-hub.ncsc.admin.chNCSC-CH GovCERThttps://security-hub.ncsc.admin.ch/#/posts/12622
- securityweek.comSecurityWeekhttps://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/
- securityweek.comSecurityWeekhttps://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/
- socradar.ioSOCRadarhttps://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/miniplasma-windows-0-day-enables-system.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
- therecord.mediaThe Recordhttps://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more
- theregister.comThe Register, 2026-05-13https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758
- theregister.comThe Registerhttps://www.theregister.com/security/2026/06/11/nightmare-eclipse-drops-claimed-bitlocker-bypass-for-microsoft-windows/5254371
- truesec.comTruesechttps://www.truesec.com/hub/blog/privilege-escalation-vulnerability-in-falcon-crowdstrike