INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft patches LegacyHive Zero-Day Vulnerability
| 2026-08-13 17:46 CRITICAL HIGHExecutive Summary AI-generated
The newly discovered vulnerability, known as LegacyHive, has been patched by Microsoft and other companies in response to a recent security update. This zero-day flaw was first reported on August 13, 2026, and affects Windows systems running older versions of the operating system. The exploit allows local attackers to gain administrator privileges, making it possible for them to modify the registry hive and execute code automatically when an admin account logs in. Microsoft has now released patches for these vulnerabilities as part of its August Patch Tuesday updates, which have been tracking this CVE since June 2026.
Technical Mitigations AI-generated
* Use Microsoft Defender for Endpoint (MDE) with the latest patches, including official LegacyHive and RoguePlanet vulnerabilities.
* Implement a layered security approach that includes:
+ User interaction is not required to exploit vulnerabilities like LegacyHive or ShieldBreak.
+ Authentication and authorization mechanisms can help prevent unauthorized access even if credentials are obtained through exploitation.
+ Regular software updates and patching can reduce the risk of future vulnerabilities.
+ Monitoring and incident response plans should be in place to quickly respond to security incidents.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-72971CVE-2026-72971
CVE-2026-62832CVE-2026-62832
CVE-2026-50656CVE-2026-50656
CVE-2026-68820CVE-2026-68820
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
legallegal
defensedefense
Incident Timeline
April 2026
Nightmare Eclipse disclosed zero-day flaws in Microsoft Windows components, including ShieldBreak and LegacyHive.
Click on any entity below to view its context and source!
infrastructure
Windows
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
ShieldBreak
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
organisation
YellowKey
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
BlueHammer
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
GreenPlasma
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
Microsoft Defender
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
organisation
BitLocker
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
MiniPlasma
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
June 2026
Threat actors used the YellowKey zero-day exploit to target fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates.
Click on any entity below to view its context and source!
infrastructure
Windows
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
organisation
YellowKey
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
BlueHammer
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
GreenPlasma
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
BitLocker
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
organisation
MiniPlasma
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday,
and the RoguePlanet vulnerability in
July
, but the other zero-days are still awaiting an official patch.
organisation
RoguePlanet
Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday,
and the RoguePlanet vulnerability in
July
, but the other zero-days are still awaiting an official patch.
general_metric
10 Windows
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
general_metric
11 Windows
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
2026/07/13
Threat actors exploited a previously unknown Windows User Profile Service privilege escalation vulnerability, CVE-2026-62832.
Click on any entity below to view its context and source!
infrastructure
Windows
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
vulnerability
CVE-2026-62832
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
tactic
Privilege Escalation
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
organisation
Windows User Profile Service
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
general_metric
7.8 score
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
July 2026
Nightmare Eclipse published a proof-of-concept exploit for the Windows User Profile Service zero-day vulnerability known as LegacyHive.
Click on any entity below to view its context and source!
infrastructure
Windows
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released,
claiming
it exploits a security vulnerability in the Windows User Profile Service.
In July, just hours after
Microsoft’s July 2026 Patch Tuesday
,
Chaotic Eclipse
,
published
a new Windows zero-day proof-of-concept called LegacyHive.
organisation
Nightmare
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released,
claiming
it exploits a security vulnerability in the Windows User Profile Service.
organisation
PoC
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released,
claiming
it exploits a security vulnerability in the Windows User Profile Service.
organisation
the Windows User Profile Service
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released,
claiming
it exploits a security vulnerability in the Windows User Profile Service.
organisation
LegacyHive
In July, just hours after
Microsoft’s July 2026 Patch Tuesday
,
Chaotic Eclipse
,
published
a new Windows zero-day proof-of-concept called LegacyHive.
July 20
Threat actors used ACROS Security's 0Patch patches to target Windows systems running Windows 10 2004 or later and Windows Server 2022 or later.
Click on any entity below to view its context and source!
infrastructure
Windows
"
ACROS Security, the company behind the 0Patch cybersecurity platform, also
released free unofficial LegacyHive patches
on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.
organisation
ACROS Security
"
ACROS Security, the company behind the 0Patch cybersecurity platform, also
released free unofficial LegacyHive patches
on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.
tactic
T1584.004 - Server
"
ACROS Security, the company behind the 0Patch cybersecurity platform, also
released free unofficial LegacyHive patches
on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.
general_metric
10 Windows
"
ACROS Security, the company behind the 0Patch cybersecurity platform, also
released free unofficial LegacyHive patches
on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.
Aug 12, 2026
Threat actors exploited a previously unknown vulnerability in Microsoft Windows to gain unauthorized access and elevate their privileges.
2026/08/13
An attacker who already has code execution as a standard user can use the User Profile Service to load another user's registry hive, potentially that of a local administrator.
Click on any entity below to view its context and source!
infrastructure
Windows
Microsoft patches LegacyHive Windows zero-day vulnerability.
The company says that LegacyHive stems from improper link resolution before file access ('link following') in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges.
"
According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
"The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate.
Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch.
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution.
Successful exploitation could enable arbitrary code execution and other unauthorized actions on affected Windows systems.
“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate.
Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”
The researcher tested the PoC on Windows 11 25H2 and Windows Server 2025 with a 100% success rate.
Windows 10 is also vulnerable, though not currently supported by the PoC.
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update.
Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025.
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as
RoguePlanet
.
ShieldBreak, on the other hand, is assessed to be a full patch bypass for CVE-2026-50656, with the researcher claiming that "Microsoft has failed to properly patch the RoguePlanet vulnerability."
"The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate," the researcher added.
"Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.
The development comes as the Windows maker
shipped
patches for
421 security flaws
, including 236 flaws in Windows.
"Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," Microsoft said.
"
Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (
CVE-2026-68820
, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (
CVE-2026-72971
, CVSS score: 5.5).
organisation
Microsoft
Microsoft patches LegacyHive Windows zero-day vulnerability.
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch.
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access.
organisation
ShieldBreak
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch.
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges.
organisation
GreenPlasma
Windows 10 is also vulnerable, though not currently supported by the PoC.
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
organisation
BitLocker
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
the Windows Collaborative Translation Framework
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
CTFMON
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
the Windows User Profile Service
This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update.
organisation
ProfSvc
This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update.
data_breach
8 bytes
Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025.
Now Chaotic Eclipse claims ShieldBreak fully bypasses Microsoft’s CVE-2026-50656 patch, while Defender may also leak 8 bytes of data under certain conditions.
organisation
CVE-2026
Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025.
organisation
Microsoft Defender
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as
RoguePlanet
.
"
Will Dormann, principal vulnerability analyst at Tharros,
confirmed
on Tuesday that the exploit works
, saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers' privileges.
In mid-June, Microsoft acknowledged the RoguePlanet zero-day affecting Microsoft Defender and stated it is aware of the issue and was actively developing a security update to address the flaw and protect affected systems.
organisation
CVSS
"
Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (
CVE-2026-68820
, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (
CVE-2026-72971
, CVSS score: 5.5).
In early July, Microsoft
released
security updates for
RoguePlanet
, a vulnerability tracked as
CVE-2026-50656
(CVSS score of 7.8) affecting the Malware Protection Engine used by Defender.
organisation
the Windows Ancillary Function
"
Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (
CVE-2026-68820
, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (
CVE-2026-72971
, CVSS score: 5.5).
organisation
Windows Container Isolation FS Filter
"
Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (
CVE-2026-68820
, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (
CVE-2026-72971
, CVSS score: 5.5).
organisation
ShieldBreak Zero-Day
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access.
organisation
Nightmare
Security researcher
Chaotic Eclipse
, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse,
released
a PoC for ShieldBreak, a Microsoft Defender zero-day.
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
organisation
INFINITE NIGHTMARE
Security researcher
Chaotic Eclipse
, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse,
released
a PoC for ShieldBreak, a Microsoft Defender zero-day.
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
organisation
MSNightmare
Security researcher
Chaotic Eclipse
, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse,
released
a PoC for ShieldBreak, a Microsoft Defender zero-day.
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
organisation
PoC
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
"Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,"
they said
.
“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass.”
said Chaotic Eclipse
.
organisation
Chaotic Eclipse
Ravie Lakshmanan
Aug 12, 2026
Zero-Day / Vulnerability
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has
released
a proof-of-concept (PoC) for a new Microsoft zero-day called
ShieldBreak
.
organisation
RoguePlanet
“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass.”
said Chaotic Eclipse
.
"RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files," Beaumont
noted
.
RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions.
organisation
YellowKey
YellowKey could allow attackers to bypass BitLocker protections, while GreenPlasma enables privilege escalation.
organisation
BlueHammer
“The vulnerabilities known as
RedSun
,
UnDefend
,
BlueHammer
,
YellowKey
, GreenPlasma, and MiniPlasma were not responsibly disclosed.”
organisation
MiniPlasma
“The vulnerabilities known as
RedSun
,
UnDefend
,
BlueHammer
,
YellowKey
, GreenPlasma, and MiniPlasma were not responsibly disclosed.”
organisation
Tharros
"
Will Dormann, principal vulnerability analyst at Tharros,
confirmed
on Tuesday that the exploit works
, saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers' privileges.
organisation
BleepingComputer
"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.
Vulnerability analyst Will Dormann
explained
that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.
BleepingComputer has contacted a Microsoft spokesperson about the new ShieldBreak zero-day and will update the story if we receive a statement.
organisation
LegacyHive
"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.
Vulnerability analyst Will Dormann
explained
that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.
organisation
Vulnerability
"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.
Vulnerability analyst Will Dormann
explained
that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.
organisation
Microsoft Defender for Endpoint
One day after the PoC was released, cybersecurity expert Kevin Beaumont also
published LegacyHive exploitation detection queries
for Microsoft Defender for Endpoint (MDE) and
confirmed that the exploit worked
.
However, cybersecurity expert Kevin Beaumont, who also
published ShieldBreak exploitation detection queries
for Microsoft Defender for Endpoint,
said
that the two exploits work very differently.
organisation
MDE
One day after the PoC was released, cybersecurity expert Kevin Beaumont also
published LegacyHive exploitation detection queries
for Microsoft Defender for Endpoint (MDE) and
confirmed that the exploit worked
.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
The Microsoft
The tech giant described it as a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll").
The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal functions.
infrastructure
7.8
In early July, Microsoft
released
security updates for
RoguePlanet
, a vulnerability tracked as
CVE-2026-50656
(CVSS score of 7.8) affecting the Malware Protection Engine used by Defender.
organisation
ShieldBreak PoC
ShieldBreak PoC exploit demo (Nightmare Eclipse)
organisation
Coordinated Vulnerability Disclosure
Microsoft’s post is essentially a public defense of Coordinated Vulnerability Disclosure, the standard practice where a researcher notifies a vendor privately, gives them time to fix the issue, and then goes public.
organisation
MSRC
The researcher criticized Microsoft for revoking access to their MSRC account, rejecting reports, and failing to provide compensation.
organisation
Microsoft’s Security Response Center
At the end of May, Microsoft’s Security Response Center
called
the zero-day dumps irresponsible.
organisation
the User Profile Service
An attacker who already has code execution as a standard user can abuse the User Profile Service to load another user’s registry hive, potentially that of a local administrator, under their own profile.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
ShieldBreak
)
organisation
The Hacker News
Microsoft told The Hacker News at the time that it's aware of the report and is investigating.
August 2026
Nightmare Eclipse released a Microsoft Defender zero-day exploit called ShieldBreak after the company's August 2026 Patch Tuesday security updates became available.
Click on any entity below to view its context and source!
organisation
Microsoft
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "
ShieldBreak
" after Microsoft released the August 2026 Patch Tuesday security updates.
organisation
Nightmare
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "
ShieldBreak
" after Microsoft released the August 2026 Patch Tuesday security updates.
August 25, 2026
Threat actors used a zero-day exploit in Microsoft Windows to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-68820
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since
added
CVE-2026-68820 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring federal agencies to apply the fixes by August 25, 2026.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since
added
CVE-2026-68820 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring federal agencies to apply the fixes by August 25, 2026.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since
added
CVE-2026-68820 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring federal agencies to apply the fixes by August 25, 2026.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since
added
CVE-2026-68820 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring federal agencies to apply the fixes by August 25, 2026.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Microsoft patches LegacyHive Windows zero-day vulnerability.
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released,
claiming
it exploits a security vulnerability in the Windows User Profile Service.
The company says that LegacyHive stems from improper link resolution before file access ('link following') in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges.
"
ACROS Security, the company behind the 0Patch cybersecurity platform, also
released free unofficial LegacyHive patches
on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.
Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including
ShieldBreak
,
LegacyHive
,
RoguePlanet
,
YellowKey
,
BlueHammer
,
RedSun
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
in Microsoft Defender, BitLocker, and other Windows components.
"
According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
"The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate.
Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.
Since April 2026, the researcher has disclosed
LegacyHive
,
RoguePlanet
,
BlueHammer
,
RedSun
,
YellowKey
,
GreenPlasma
,
MiniPlasma
, and
UnDefend
zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in
July
and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the
June 2026 Patch Tuesday
, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch.
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution.
Successful exploitation could enable arbitrary code execution and other unauthorized actions on affected Windows systems.
“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate.
Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
The researcher tested the PoC on Windows 11 25H2 and Windows Server 2025 with a 100% success rate.
Windows 10 is also vulnerable, though not currently supported by the PoC.
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
In July, just hours after
Microsoft’s July 2026 Patch Tuesday
,
Chaotic Eclipse
,
published
a new Windows zero-day proof-of-concept called LegacyHive.
This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update.
Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025.
One of the patches involves
CVE-2026-62832
(CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name
LegacyHive
.
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as
RoguePlanet
.
ShieldBreak, on the other hand, is assessed to be a full patch bypass for CVE-2026-50656, with the researcher claiming that "Microsoft has failed to properly patch the RoguePlanet vulnerability."
"The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate," the researcher added.
"Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.
The development comes as the Windows maker
shipped
patches for
421 security flaws
, including 236 flaws in Windows.
"Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," Microsoft said.
"
Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (
CVE-2026-68820
, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (
CVE-2026-72971
, CVSS score: 5.5).
Metrics
infrastructure
7.8
Software Version
In early July, Microsoft
released
security updates for
RoguePlanet
, a vulnerability tracked as
CVE-2026-50656
(CVSS score of 7.8) affecting the Malware Protection Engine used by Defender.
Metrics
data_breach
8
Bytes
Now Chaotic Eclipse claims ShieldBreak fully bypasses Microsoft’s CVE-2026-50656 patch, while Defender may also leak 8 bytes of data under certain conditions.
Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025.
Intelligence Sources
Security Affairs
2026-08-12
The Hacker News
2026-08-12
BleepingComputer
2026-08-12
BleepingComputer
2026-08-13
Microsoft patches LegacyHive Windows zero-day vulnerability
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-14T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
40x
organisation
Identified Entity
Microsoft
entity
12x
timeline
Temporal Reference
July 2026
date
4x
vulnerability
Exploited CVE
CVE-2026-62832
cve
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
general metric
Score
8
score
3x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
2x
general metric
Windows
10
windows
2x
industry
Targeted Sector
Legal
sector
Contextual Telemetry
Context Block
12 METRICS
infrastructure
Affected Product
Windows
software
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
tactic
Cyber Operation Type
Privilege Escalation
tactic
general metric
%
100
%
target region
Target Country
United States
country
vulnerability
CVSS Score
8
score
infrastructure
Software Version
7.8
version
data breach
Bytes
8
bytes
general metric
Security Flaws
421
security flaws
general metric
Flaws
236
flaws
general metric
Aug
12
aug
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.