AI Weekly Malaysia

Back to items Summaries

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

ID
13694
Status
summarized
Published
13 Aug 2026, 2:12 AM
Fetched
13 Aug 2026, 6:05 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
5.0
Created
13 Aug 2026, 7:09 AM
Tags
Audience
developerssaas_startup_founders

What happened

A hacker known as Nightmare Eclipse published ShieldBreak, the 10th Windows zero-day in their campaign against Microsoft, a local privilege-escalation exploit that gains SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server 2025. Former Microsoft employee Kevin Beaumont confirmed it works on the latest Windows 11 and published three detection and hunting queries. The exploit bypasses Microsoft's July fix for CVE-2026-50656 (RoguePlanet) but operates differently, abusing Defender's cloud-hydration scan via the Cloud Filter API.

Why it matters

If you run Windows Server or Windows desktops in production, apply Beaumont's hunting queries now since Microsoft has not yet patched ShieldBreak and the PoC has a claimed 100% success rate on Windows 11 25H2. Because this is a local privilege-escalation exploit (not remote), the immediate risk is to multi-tenant or shared Windows environments where an attacker already has low-level access.

Discussion angle

How many of us actually run Windows Server or Windows desktops in production infrastructure versus Linux/cloud-native stacks — and does a confirmed LPE zero-day with public PoC change anything for those who don't?

Top