Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Defender Patch Bypass: New Zero-Day Vulnerability

Microsoft Defender Patch Bypass: New Zero-Day Vulnerability

Posted on August 12, 2026 By CWS

A cybersecurity researcher known by the aliases Chaotic Eclipse and Nightmare-Eclipse has unveiled a proof-of-concept (PoC) for a new zero-day vulnerability dubbed ShieldBreak. This vulnerability affects Microsoft Defender on Windows systems, specifically targeting a patch bypass for CVE-2026-50656, also referred to as RoguePlanet.

Understanding the RoguePlanet Vulnerability

RoguePlanet is characterized as a race condition vulnerability, which, if exploited, allows attackers to gain SYSTEM-level privileges. This capability enables unauthorized execution of code and other malicious activities. Initially revealed in June 2026, Microsoft addressed this vulnerability with a patch nearly a month later, identifying it as a privilege escalation issue within the Microsoft Malware Protection Engine, known as ‘mpengine.dll’.

Despite Microsoft’s efforts, Chaotic Eclipse reported that the updates intended to secure CVE-2026-50656 inadvertently led to data leakage issues in specific scenarios on Windows 11 25H2 and Windows Server 2025. The tech company acknowledged the report and is conducting further investigations.

ShieldBreak: A Full Patch Bypass

The newly disclosed ShieldBreak vulnerability represents a complete patch bypass for the RoguePlanet issue. Chaotic Eclipse claims that Microsoft’s patch was insufficient, leaving the system vulnerable. The researcher confirmed that the PoC has demonstrated a 100% success rate on the latest Windows 11 25H2 and Windows Server 2025 versions, although Windows 10 remains susceptible despite not being tested.

The Hacker News has reached out to Microsoft for comments regarding this situation. Any updates from the company will be added as they become available.

Microsoft’s Ongoing Security Challenges

This revelation coincides with Microsoft’s release of fixes for 421 security vulnerabilities, including 236 specific to Windows. Among these, CVE-2026-62832, another privilege escalation vulnerability disclosed by Chaotic Eclipse, was addressed. This flaw, named LegacyHive, arises from improper link resolution in the Windows User Profile Service, potentially allowing attackers to access and modify user data.

Furthermore, Microsoft patched an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820) and a tampering vulnerability in the Windows Container Isolation FS Filter Driver (CVE-2026-72971). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to apply these patches by August 25, 2026.

The emergence of ShieldBreak underscores the ongoing challenges faced by tech giants in securing their systems against sophisticated vulnerabilities. As cybersecurity threats evolve, the need for robust and timely solutions becomes increasingly critical.

The Hacker News Tags:Chaotic Eclipse, CVE-2026-50656, Cybersecurity, Microsoft Defender, patch bypass, RoguePlanet, ShieldBreak, SYSTEM access, Vulnerability, zero-day

Post navigation

Previous Post: Sandworm Exploits Job Interviews to Deploy Malicious VPNs
Next Post: Intel and AMD Address Over 80 Security Flaws

Related Posts

Microsoft Releases RAMPART and Clarity for AI Security Microsoft Releases RAMPART and Clarity for AI Security The Hacker News
GigaWiper Malware: A New Threat to Windows Systems GigaWiper Malware: A New Threat to Windows Systems The Hacker News
New SparkCat Malware Targets Crypto Wallets on Mobile Apps New SparkCat Malware Targets Crypto Wallets on Mobile Apps The Hacker News
Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with 0K in Rewards Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards The Hacker News
INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty The Hacker News
Injective Labs GitHub Breach Exposes Crypto Wallets Injective Labs GitHub Breach Exposes Crypto Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark