CriticalSecurity & Privacy
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
A security researcher has publicly disclosed a critical Windows zero-day vulnerability (ShieldBreak) affecting Windows 10, 11, and Server 2025 that enables privilege escalation and full system compromise through Windows Defender, despite Microsoft's legal threats against such disclosures. This incident escalates the escalating tension between Microsoft and the security research community over vulnerability handling practices, leaving organizations exposed until Microsoft releases a patch. IT leaders face immediate risk exposure and must reassess their Windows security posture while navigating the broader implications of vendor-researcher relationships on coordinated vulnerability disclosure.

This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.