Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Defender Zero-Day Vulnerability Exposes System Access

Microsoft Defender Zero-Day Vulnerability Exposes System Access

Posted on June 14, 2026 By CWS

An anonymous security expert, known as Chaotic Eclipse, recently published a proof-of-concept (PoC) exploit targeting a zero-day vulnerability in Microsoft Defender, named RoguePlanet. This exploit, which involves a race condition, can yield SYSTEM-level access, potentially allowing malicious actors to execute arbitrary code on affected systems.

Exploit Details and Impact

The exploit has been tested on Windows 11 and Windows 10 systems that have received the June 2026 Patch Tuesday updates, indicating it affects the latest versions of these operating systems. However, it currently does not work on Windows Server instances. Chaotic Eclipse highlighted that the flaw still exists in Windows Server, but the exploit’s design requires adjustments to affect those systems.

Security researcher Will Dormann noted on Mastodon that, while the exploit is not consistently reliable, it functioned successfully on his initial attempt. The exploit raises significant concerns as it can grant attackers unauthorized access to perform harmful actions on compromised systems.

Researcher Disputes and Microsoft’s Stance

Chaotic Eclipse has been involved in ongoing disputes with Microsoft, accusing the company of mishandling vulnerability disclosures and revoking their access to the Microsoft Security Response Center (MSRC). This tension has led to uncoordinated public disclosures of several vulnerabilities, including RoguePlanet, as a form of retaliation.

Microsoft has criticized the public release of such vulnerabilities, arguing that they pose unnecessary risks to users. The company maintains that coordinated vulnerability disclosure is crucial for protecting customers and addressing security issues effectively.

Future Outlook and Reactions

In response to these disclosures, Microsoft stated that it is investigating the reported vulnerabilities and is committed to updating affected products promptly. The company emphasized its support for coordinated vulnerability disclosure to ensure thorough investigation and remediation of security flaws before public disclosure.

The ongoing conflict between Chaotic Eclipse and Microsoft highlights the challenges in vulnerability disclosure processes and the need for clear communication between researchers and companies. As this situation unfolds, the cybersecurity community will be closely monitoring Microsoft’s actions and any further disclosures by Chaotic Eclipse.

The Hacker News Tags:Cybersecurity, Exploit, Microsoft Defender, patch updates, security flaws, SYSTEM access, Vulnerability, Windows 10, Windows 11, zero-day

Post navigation

Previous Post: ServiceNow Security Breach Allows Unauthorized Access
Next Post: Critical Vulnerabilities in Protobuf.js Threaten Node.js Security

Related Posts

What is Identity Dark Matter? What is Identity Dark Matter? The Hacker News
Security Flaw in GitHub Action Exposes Repositories Security Flaw in GitHub Action Exposes Repositories The Hacker News
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces The Hacker News
JetBrains Plugins Exploit AI API Keys; Chrome Extensions Leak AI Chats JetBrains Plugins Exploit AI API Keys; Chrome Extensions Leak AI Chats The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News
Why Top Teams Are Prioritizing Code-to-Cloud Mapping in Our 2025 AppSec Why Top Teams Are Prioritizing Code-to-Cloud Mapping in Our 2025 AppSec The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation
  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation
  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark