daily cyber × ai intelligence

index

tagged

[CVE-2026-50656]

4 editions · 4 items

August 13, 2026

  • The "ShieldBreak" zero-day PoC bypasses Microsoft's fix for CVE-2026-50656 (RoguePlanet), a Defender flaw, and grants SYSTEM from any user account. The researcher — going by Nightmare Eclipse / Chaotic Eclipse / MSNightmare — published working code, and where RoguePlanet was a quarantine filesystem race condition, ShieldBreak instead abuses a user-mode callback hook, per BleepingComputer and The Hacker News. Kevin Beaumont has already published a ShieldBreak hunting KQL query; the PoC is on GitHub. (discussion) · Offensive & Exploitation

in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

July 10, 2026

  • Microsoft patched RoguePlanet (CVE-2026-50656), a CVSS 7.8 privilege-escalation flaw in the Malware Protection Engine (mpengine.dll) that can grant SYSTEM, nearly a month after researcher "Nightmare-Eclipse" published a PoC following June Patch Tuesday. The same researcher separately detailed additional Defender mpengine.dll behavior allowing data leakage and system hangs via malicious SMB/WebDAV servers abusing ADS caching. BleepingComputer · The Hacker News · PNC Blog · Malware & Endpoint Evasion

in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0