Vengeful researcher bypasses Microsoft’s Patch Tuesday fix with new Windows zero-day
Now famous researcher under the alias Nightmare Eclipse, was “too lazy” to release a full exploit

Microsoft Windows logo. Photo by Samuel Boivin/NurPhoto via Getty Images)
- Nightmare Eclipse released ShieldCrash, a proof-of-concept that allegedly bypasses Microsoft’s ShieldBreak Defender patch.
- The exploit could let a low-privileged attacker with local code execution read protected files as SYSTEM.
- The researcher claims ShieldCrash worked on Windows 11 25H2 and Windows Server 2025 in testing.
- Coincides with Patch Tuesday in which Microsoft said it had addressed 966 vulnerabilities, including 2 zero-days already used in attacks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Microsoft's patch for the ShieldBreak Defender vulnerability is still bypassable, according to Nightmare Eclipse, the vengeful researcher who has become a constant scourge for the big tech firm's monthly disclosure day, Patch Tuesdays.
The anonymous researcher released a new proof-of-concept exploit called ShieldCrash, claiming it bypasses Microsoft's patch for the ShieldBreak Defender vulnerability – the latest in a string of Windows zero-day disclosures.
The exploit lets an attacker, who already has local code execution, trick Defender into performing an arbitrary file read as SYSTEM. This enables a low-privileged process to access and leak files it normally couldn't reach.
Nightmare Eclipse claims that the PoC was tested against Windows 11 25H2, including Canary Channel builds, and Windows Server 2025, with a 100% success rate.
The researcher, also known as Chaotic Eclipse, MSNightmare, and, more recently, Infinite Nightmare, says the exploit runs on all supported Windows versions running the September 2026 patches.
Proof-of-concept details flaw
They shared what they called a "skeleton PoC" on GitHub (under their Infinite Nightmare moniker) as well as independent repos Church of Malware and Project NightCrawler.
These disclosures were also widely shared on X.
The researcher – who has been plaguing Windows with exploit disclosures since April amid a bitter bug bounty/vulnerability disclosure beef with Microsoft – said that they might eventually release a full exploit.
Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak,– Nightmare Eclipse/ Infinite Nightmare.
Giving off a hint of casual arrogance, they added that, for now, the proof-of-concept (PoC) would have to do, as they were “feeling a bit lazy.”
Patch Tuesday: MS claimed to fix over 900 flaws
ShieldCrash arrived as administrators were dealing with an enormous September Patch Tuesday, which Microsoft claimed addressed 966 vulnerabilities, including 105 rated “critical” and 2 zero-days already being exploited in attacks.
It’s already a tradition for the anonymous researcher Nightmare Eclipse, who blames Microsoft for ruining their life, to drop a new zero-day vulnerability immediately after a Patch Tuesday.
The ShieldCrash issue appears to be the latest step in a chain of Windows Defender vulnerabilities. RoguePlanet was the original local privilege-escalation issue – Microsoft patched it, but then Nightmare released ShieldBreak, which bypassed parts of that fix.
Microsoft patched ShieldBreak as well, but with ShieldCrash Nightmare claims that this wasn’t properly resolved.
CrowdStrike targeted with FalconFlank
On September 3rd, Nightmare Eclipse surprised the community by taking aim at a different target: CrowdStrike, with FalconFlank, a PoC targeting the big tech security firm’s Falcon for malicious macro remediation functionality.
CrowdStrike reportedly urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the firm investigates the case.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Since April, the controversial hacker’s main target has been Microsoft, disclosing a long string of zero-day flaws, including LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.