September 12, 2026
- ShieldCrash — Dark Reading reports that Nightmare-Eclipse published another claimed Windows Defender zero-day exploit. This establishes public exploit availability, not active exploitation, and is distinct from ShieldBreak/CVE-2026-69414 (earlier coverage).
· New Tools & Releases
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 9, 2026
- A published PoC bypasses Microsoft's patch for the Windows Defender flaw CVE-2026-69414 ("ShieldBreak"). Researcher Nightmare Eclipse released ShieldCrash, demonstrating arbitrary file read as SYSTEM on supported Windows versions with the September 2026 updates applied; he calls it a "skeleton PoC" and says a full SYSTEM exploit may follow (@IntCyberDigest, repo, Microsoft advisory). The repo was empty when first spotted and populated later, so check what you pull. No in-the-wild exploitation of the bypass has been reported.
· Exploits & Vulnerability Research
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 17, 2026
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover