Home / Aug 14, 2026 / Story
0
#2 SecurityWeek general August 13, 2026 at 08:38 UTC

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

By Ionut Arghire

AI Summary

A threat actor known as Nightmare Eclipse (also Chaotic Eclipse/MSNightmare) dropped a zero-day PoC exploit called 'ShieldBreak' on August 2026 Patch Tuesday, demonstrating a patch bypass for CVE-2026-50656 (CVSS 7.8, aka RoguePlanet) in Microsoft Defender that allows any unprivileged user to spawn a shell with SYSTEM privileges. The exploit was released after Microsoft's patch cycle, leaving a window of exposure for unpatched systems. Security teams should prioritize applying the August Patch Tuesday updates immediately.

Relevance score: 90.0/100

# More from August 14