Nightmare Eclipse Strikes Again with New Zero-Day Vulnerability in Windows
Notorious researcher Nightmare Eclipse has struck again, releasing a new zero-day vulnerability called ShieldBreak that allows threat actors to gain SYSTEM-level privileges on vulnerable Windows systems. The flaw was discovered in fully updated versions of Windows 11 and can bypass recent security patches.
Nightmare Eclipse's campaign began in April 2026 with the release of BlueHammer, a local privilege-escalation flaw in Windows Defender that gave low-privileged users SYSTEM-level access. Since then, they have released several other exploits, including RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, GreatXML, and LegacyHive.
The researcher claimed that the latest vulnerability, ShieldBreak, is a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet. However, security expert Kevin Beaumont confirmed that ShieldBreak operates differently from RoguePlanet and is more dangerous in that respect.