A security researcher using the name Nightmare Eclipse has published details of a new Windows zero-day vulnerability, according to TechCrunch. The bug, called ShieldBreak, reportedly affects recent versions of Windows and allows an attacker to move from low-level user permissions to broad access over the device and its data. TechCrunch reports that ShieldBreak targets Windows Defender, Microsoft’s built-in anti-malware and security engine. Nightmare Eclipse published a proof-of-concept exploit as a Windows app, meaning a user must run the app for the exploit to be triggered, according to the report. The researcher said the bug works on Windows 10, Windows 11, including the latest 25H2 version, and Windows Server 2025, TechCrunch reports. Security researcher Will Dormann verified that the exploit works and that Windows Defender must be enabled for it to operate, according to the same story. Microsoft had not released a patch for ShieldBreak at the time of TechCrunch’s report. TechCrunch said Microsoft did not immediately comment when contacted. The vulnerability is being treated as a zero-day because Microsoft was not given time to patch before public disclosure, according to the report. ShieldBreak appears to build on a prior Nightmare Eclipse exploit called RoguePlanet, TechCrunch reports, citing the researcher. Microsoft had issued a patch for RoguePlanet, but Nightmare Eclipse implied that the new exploit shows a full bypass of that earlier fix. The cluster does not include Microsoft’s account of whether the RoguePlanet patch was complete or how it evaluates the new disclosure. The new release extends a dispute between Nightmare Eclipse and Microsoft over vulnerability reporting. TechCrunch reports that the researcher has claimed in blog posts that Microsoft mishandled their reports, leading them to publish bugs publicly. The outlet also notes that Nightmare Eclipse previously released other Windows bugs that were later used in real-world attacks against organizations. The disclosure lands in a sensitive moment for Microsoft’s security operation. TechCrunch says Microsoft published a May blog post threatening legal action against researchers who release zero-days outside company disclosure policies, drawing criticism from parts of the security community. Microsoft later walked back those comments in a social media post, according to TechCrunch, though the original blog post remained online unchanged. ShieldBreak was published one day after Microsoft’s monthly Patch Tuesday release, TechCrunch reports. The outlet says this was the second month in a row in which Microsoft’s patch count reached roughly 500 bugs, driven by the company’s growing use of artificial intelligence to find and remove security flaws. Who benefits: Attackers benefit if they can get code run on a Windows system and then use ShieldBreak to raise privileges, as described by TechCrunch. Security researchers also gain a concrete test case for Microsoft’s patching and disclosure process. Who's exposed: Organizations running Windows 10, Windows 11, or Windows Server 2025 with Windows Defender enabled are the population named in the report. The actual exposure depends on whether an attacker can get the proof-of-concept or related code executed on a target machine.