A researcher Microsoft threatened with legal action just published another Windows zero-day

Microsoft threatened a security researcher with legal action to stop them from publishing vulnerabilities. The researcher published another one anyway. That sequence of events tells you almost everything you need to know about how broken the relationship between big software companies and independent security researchers has become.

The new bug is called ShieldBreak, and it’s serious. As reported by TechCrunch, the researcher behind it goes by Nightmare Eclipse, who has spent recent months publishing a string of Windows vulnerabilities, many of which Microsoft has been slow to address. ShieldBreak targets Windows Defender, the security engine built directly into Windows. A successful attack lets someone escalate from a low-level user account to full, system-wide access. That means your files, your credentials, your everything.

The exploit works on Windows 10, Windows 11 (including the latest 25H2 build), and Windows Server 2025. Nightmare Eclipse released it as a proof-of-concept Windows app, meaning a target would need to run it. But that bar is lower than it sounds. Independent researcher Will Dormann confirmed the bug works, with one condition: Windows Defender has to be enabled. So the very tool meant to protect you is what makes the attack possible. That’s a rough irony for Microsoft’s security team.

This isn’t Nightmare Eclipse’s first move. The researcher previously published a bug called RoguePlanet, which Microsoft patched. ShieldBreak appears to be a direct bypass of that fix, suggesting Microsoft’s patch didn’t go far enough. Microsoft has not released any fix for ShieldBreak yet, which makes it a zero-day by definition. A company spokesperson said Microsoft is “aware of the reported vulnerability and is actively investigating.” That’s standard boilerplate.

The backstory here matters. Nightmare Eclipse has accused Microsoft of mishandling their bug reports repeatedly, leaving them feeling like public disclosure was the only way to force action. In May, Microsoft responded not with better processes but with a blog post threatening legal action against researchers who publish outside the company’s preferred disclosure policy. The security community pushed back hard, with many sharing similar frustrations. Microsoft eventually softened the statement on social media. The original blog post still stands, unchanged.

ShieldBreak dropped the day after Patch Tuesday, Microsoft’s monthly security update cycle. That timing is almost certainly not a coincidence. And this Patch Tuesday was notable on its own: Microsoft closed around 500 bugs, a number the company attributes to its growing use of AI to find flaws. Finding them faster is good. But it also raises a question worth sitting with: if AI is surfacing hundreds of bugs at a time, how many more are still sitting unpatched while Microsoft decides whether to fix them or threaten the people who find them?