Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Defender SYSTEM privilege escalation bypass (CVE-2026-69414)

Vulnerability
First reported
Last updated
Happening score
H score 28
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft Defender vulnerability CVE-2026-69414 is back in focus after Chaotic Eclipse released ShieldCrash, a patch bypass for ShieldBreak. The PoC shows arbitrary file read as SYSTEM on the latest Windows release, and the article says all supported desktop Windows versions are impacted. Microsoft said the issue was patched in Microsoft Malware Protection Engine 1.1.26080.3, after a recent September 2026 Patch Tuesday update to plug the flaw. The release adds a public bypass path against a recently patched Defender weakness.

Related Happenings

Microsoft Defender Antivirus false 'turned off' alerts after latest updates

Security Tool/Service
H score11 First: 31.08.2026 11:29 Last: 31.08.2026 11:29 Sources 1

About this happening: Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...

Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11

Security Tool/Service
H score11 First: 19.08.2026 14:14 Last: 19.08.2026 14:14 Sources 1

About this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...

Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave

Exploitation Wave
H score41 First: 30.06.2026 11:53 Last: 30.06.2026 11:53 Sources 1

About this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...

Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw

Vulnerability
H score39 First: 10.06.2026 02:11 Last: 10.06.2026 02:11 Sources 1

About this happening: Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly...

Latest development: 10.06.2026 08:22

The anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.

Windows BitLocker YellowKey mitigation guidance (CVE-2026-45585)

Advisory/Mitigation
H score32 First: 20.05.2026 10:31 Last: 20.05.2026 10:31 Sources 1

About this happening: Windows BitLocker YellowKey (CVE-2026-45585) moved from interim mitigation to patch status after Microsoft fixed it in June 2026 Patch Tuesday. The Windows R...

Latest development: 10.06.2026 12:57

On Tuesday, Microsoft fixed YellowKey (CVE-2026-45585) as part of its June 2026 Patch Tuesday updates and shared mitigation measures for the Windows Recovery Environment backdoor. The flaw affects unpatched Windows 11 and Windows Server 2022/2025 systems and can let attackers with physical access bypass BitLocker protection on targeted devices.

Timeline

  1. 09.09.2026 10:30 3 articles · 2h ago

    Nightmare Eclipse releases ShieldCrash bypass for Microsoft Defender

    Initial Disclosure

    Nightmare Eclipse released ShieldCrash, a zero-day proof-of-concept for Microsoft Defender that bypasses ShieldBreak CVE-2026-69414 and can reportedly grant SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems without write access. The release came right after Microsoft rolled out its September 2026 Patch Tuesday security updates, and the proof-of-concept is described as demonstrating an arbitrary file read as SYSTEM under September 2026 conditions.

    Show sources