Security researcher Nightmare-Eclipse has published a new proof-of-concept exploit called ShieldCrash on GitHub, claiming it circumvents Microsoft's fix for CVE-2026-69414 (ShieldBreak), a privilege escalation bug in the Malware Protection Engine. The exploit reportedly allows arbitrary file reads as SYSTEM on all supported Windows versions, despite Microsoft's September patch. Microsoft has not yet responded to requests for comment on the claim.
darkreading.com
· 2026-09-10
A researcher using the alias Nightmare Eclipse publicly released details of a new zero-day exploit dubbed 'ShieldCrash' targeting Microsoft Defender, timed to appear right after Microsoft's September 2026 Patch Tuesday updates. The exploit reportedly allows attackers to gain SYSTEM-level access on affected Windows machines, the highest level of privilege on the system.
bleepingcomputer.com
· 2026-09-09
A researcher going by 'Nightmare Eclipse' released a privilege-escalation exploit dubbed FalconFlank that abuses CrowdStrike Falcon's malicious macro remediation feature to gain SYSTEM-level command prompt access on fully patched Windows 11 25H2 and Windows Server 2025 machines. The flaw has no CVE yet, and CrowdStrike says it is investigating while telling customers to disable the Office File Suspicious Macro Removal policy setting as a workaround.
bleepingcomputer.com
· 2026-09-04