A security researcher known as Nightmare Eclipse has disclosed a new Windows vulnerability called ShieldBreak, describing a flaw that could let an attacker move from limited access to full control of a device and its data.
The issue reportedly affects the security engine built into Windows Defender and works on Windows 10, Windows 11 including version 25H2, and Windows Server 2025. The proof-of-concept was shared as a Windows app that must be run by the user for the exploit to activate.
Independent verification from security researcher Will Dormann confirmed that the exploit works when Windows Defender is enabled. The disclosure follows an earlier bug from the same researcher, called RoguePlanet, which Microsoft had already patched.
Nightmare Eclipse says ShieldBreak may bypass that earlier fix, while Microsoft has not yet issued a patch for the newly published flaw. Because the company had no time to address it before disclosure, the issue is being treated as a zero-day.
The release also arrives amid a broader debate over how major software makers and security researchers coordinate vulnerability reporting. Microsoft has recently expanded its use of AI to identify more flaws, contributing to a much larger monthly patch cycle.
As security tooling becomes more advanced, rapid disclosure and faster remediation may shape a more resilient digital ecosystem in the years ahead.