A security researcher known as Nightmare Eclipse has disclosed a critical vulnerability in Windows despite receiving legal threats from Microsoft. The flaw, called ShieldBreak, exploits a weakness in Windows Defender that could allow attackers to gain complete control over an infected system. The vulnerability affects Windows 10, Windows 11, and Windows Server 2025.
ShieldBreak represents the latest in a series of zero-day disclosures by Nightmare Eclipse targeting Microsoft products. The researcher claims the bug bypasses a previous patch that Microsoft released for an earlier exploit called RoguePlanet. While an independent security researcher confirmed the vulnerability works, Microsoft has not yet issued a patch and declined to comment on the matter.
This disclosure follows Microsoft’s May threat to pursue legal action against researchers who publicly reveal zero-day vulnerabilities outside the company’s established reporting channels. The technology community widely criticized that stance, with many security experts reporting similar frustrations with Microsoft’s bug-handling procedures. Microsoft later softened its position through social media but left the original blog post unchanged.
The publication of ShieldBreak comes just one day after Microsoft’s monthly security update cycle, demonstrating the ongoing tension between independent security researchers and the software giant over vulnerability disclosure practices.
