New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek.
The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches.
Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation.
The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare.
Source: https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/
Related breach coverage
- Pixel Modem Zero-Day Exploited in Targeted Attacks2026-09-16
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation2026-09-15
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.
- Oracle Patches 800+ Vulnerabilities in September 2026 Security Update2026-09-16
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days2026-09-12
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.