A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day proof of concept called ShieldBreak, according to BleepingComputer. The report says the exploit appeared after Microsoft issued its August 2026 Patch Tuesday security updates. ShieldBreak is described as a bypass for RoguePlanet, another Microsoft Defender privilege-escalation flaw that Nightmare Eclipse disclosed in June and Microsoft patched one month later. The researcher alleges Microsoft did not fully fix RoguePlanet, identified in the report as CVE-2026-50656, and that the new proof of concept demonstrates a full patch bypass. The material claim is local privilege escalation: according to BleepingComputer, Nightmare Eclipse says ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The researcher said the proof of concept was tested on Windows 11 25H2 Canary builds and Windows Server 2025, while also saying Windows 10 and related server editions are vulnerable even though the PoC does not currently support them. BleepingComputer also reports that Will Dormann, principal vulnerability analyst at Tharros, confirmed on Tuesday that the exploit works. Dormann said Microsoft Defender must be enabled for ShieldBreak to escalate privileges, according to the report. The disclosure lands in the middle of a continuing dispute between Microsoft and Nightmare Eclipse over vulnerability disclosure and bug bounty practices. BleepingComputer says Microsoft previously responded to the researcher’s disclosures by warning about legal action against people involved in “malicious activity causing real harm” to customers, a response that some cybersecurity experts interpreted as a direct warning to the researcher. Since April 2026, Nightmare Eclipse has disclosed multiple zero-days affecting Microsoft Defender, BitLocker, and Windows components, according to BleepingComputer. The report names LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend among those disclosures. The patch status is uneven. BleepingComputer reports that Microsoft fixed RoguePlanet in July and fixed YellowKey, GreenPlasma, and MiniPlasma in the June 2026 Patch Tuesday cycle, while other vulnerabilities disclosed by Nightmare Eclipse were still awaiting official patches. BleepingComputer said it contacted Microsoft about ShieldBreak and would update its story if the company responded. Who benefits: Attackers benefit most from a public proof of concept if they can reproduce the privilege escalation. Defenders benefit from early notice that the RoguePlanet patch may not close the reported attack path. Who's exposed: The report points to Windows 10, Windows 11, and Windows Server systems, with the strongest PoC testing claim tied to Windows 11 25H2 Canary and Windows Server 2025. Systems with Microsoft Defender enabled are specifically relevant, according to Dormann as cited by BleepingComputer.