#2
SecurityWeek
general
August 13, 2026 at 08:38 UTC
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
By Ionut Arghire
AI Summary
A threat actor known as Nightmare Eclipse (also Chaotic Eclipse/MSNightmare) dropped a zero-day PoC exploit called 'ShieldBreak' on August 2026 Patch Tuesday, demonstrating a patch bypass for CVE-2026-50656 (CVSS 7.8, aka RoguePlanet) in Microsoft Defender that allows any unprivileged user to spawn a shell with SYSTEM privileges. The exploit was released after Microsoft's patch cycle, leaving a window of exposure for unpatched systems. Security teams should prioritize applying the August Patch Tuesday updates immediately.
Relevance score: 90.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →