When a security researcher publishes a zero-day vulnerability, the decision often comes down to trust — and in this case, that trust has clearly eroded. A researcher known as Nightmare Eclipse has just released details of a new Windows flaw called ShieldBreak, a move made despite Microsoft explicitly threatening legal action against such disclosures just weeks earlier. Main Developments ShieldBreak targets a weakness inside Windows Defender, the built-in anti-malware engine that ships with every modern Windows installation. Exploiting the flaw lets an attacker jump from a low-level user account to full system-wide access, effectively taking over the device and everything stored on it. Read also: Road to Battlefield Returns for Second Year Across Central Eurasia Nightmare Eclipse published the proof-of-concept as a Windows app, meaning the exploit requires a user to actually run the downloaded program. The researcher confirmed the bug affects Windows 10, Windows 11 including the latest 25H2 update, and Windows Server 2025. Independent verification came from security researcher Will Dormann, who confirmed the exploit works — but only when Windows Defender is actively enabled. That detail matters because it means the attack surface includes nearly every default Windows installation. Background ShieldBreak is not an isolated incident. It builds directly on an earlier exploit from the same researcher called RoguePlanet, which Microsoft patched. Nightmare Eclipse, however, implies that fix was incomplete, and ShieldBreak demonstrates a full bypass of that earlier patch. The relationship between the researcher and Microsoft has grown increasingly hostile. In a series of blog posts, Nightmare Eclipse accused the company of mistreating them and failing to properly handle their bug reports, framing public disclosure as the only remaining option. That tension escalated in May when Microsoft published a blog post threatening legal action against researchers who release zero-day details outside its disclosure policies. The security community pushed back hard, with many researchers saying they had experienced similar treatment. Microsoft later softened its stance in a social media post, though the original blog post remains unchanged and online. Why It Matters The timing of this disclosure is particularly pointed. ShieldBreak landed the day after Microsoft's monthly Patch Tuesday, a release cycle that has grown dramatically larger in recent months. For the second consecutive month, the company patched roughly 500 bugs — a spike driven largely by its increased reliance on AI to identify security flaws. Because this is a zero-day, Microsoft had no advance notice to prepare a fix. The company said it is aware of the reported vulnerability and is actively investigating its validity and potential applicability — language that suggests a patch is not imminent. Nightmare Eclipse previously released other Windows bugs that were later exploited in real-world attacks against organizations. That history raises the stakes for this disclosure, as threat actors may now race to weaponize ShieldBreak before Microsoft ships a fix. What's Next Microsoft has not yet released a patch for ShieldBreak, and no timeline has been announced. The company's investigation is ongoing, and the security community will be watching closely to see whether the fix arrives on an emergency basis or waits for the next Patch Tuesday cycle. For Nightmare Eclipse, the legal risk remains unresolved. Microsoft's earlier threat of legal action was walked back in tone but not in writing, leaving the question open of whether the company will follow through on its original stance. The broader security community, meanwhile, is likely to keep scrutinizing how Microsoft handles researcher disclosures — and whether public shaming becomes a more common tactic.