The security researcher known as Nightmare Eclipse has publicly released a new proof-of-concept (PoC) exploit, named "HardBreacher," which targets a privilege escalation vulnerability in Kaspersky Endpoint Security. This disclosure follows a pattern of the researcher releasing zero-day exploits, often after expressing frustration with vendor vulnerability handling processes.
The HardBreacher exploit specifically targets a privilege escalation flaw within Kaspersky's endpoint security product. According to Nightmare Eclipse, successful exploitation can lead to the operating system becoming unstable, with the ability to disrupt Kaspersky's UI process and manipulate file access controls. The researcher noted the PoC was not fully refined but demonstrated the vulnerability's potential impact.
In response to the public disclosure, Kaspersky confirmed that the underlying security issue has been addressed. The company stated that a fix has been delivered to users through an automatic update, and users can also manually trigger a database update to ensure their systems are protected. This rapid response aims to mitigate the risk posed by the publicly available exploit.
Nightmare Eclipse, also known as Chaotic Eclipse, has a history of disclosing zero-day vulnerabilities and releasing PoC exploits, primarily for Windows and Microsoft Defender flaws. Previous exploits include "ShieldBreak" and "LegacyHive," both of which enabled privilege escalation. The researcher's motivation for public disclosure has been cited as dissatisfaction with how some vendors handle vulnerability reports, leading to a series of public releases of security flaws.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A zero-day proof-of-concept tool named BigDiskBuster was released on GitHub, which prevents Microsoft Defender from updating by consuming all available disk space. This tool, created by a former Microsoft security researcher, has no current patch or CVE, potentially leaving systems vulnerable to outdated Defender definitions.
The researcher known as Nightmare Eclipse, now identified as Abdelhamid Naceri, released a new proof-of-concept exploit called BigDiskBuster for Microsoft Defender. This exploit prevents Defender from updating its platform and signatures, working on all supported Windows versions.
Security researcher Abdelhamid Naceri released a new zero-day exploit, named BigDiskBuster, that allows standard users to block Microsoft Defender antivirus updates on all supported Windows versions. This exploit prevents Defender from performing platform and signature updates, potentially leaving systems vulnerable.
Security researcher Nightmare Eclipse released 'ShieldCrash', a new zero-day exploit for Microsoft Defender that allows privilege escalation on fully patched Windows systems. This exploit bypasses previous patches for similar vulnerabilities, indicating an incomplete fix for the underlying security flaw.
A security researcher released a new zero-day exploit named "ShieldCrash" for Microsoft Defender, which grants SYSTEM access. This exploit was disclosed immediately after Microsoft's September 2026 Patch Tuesday updates, indicating a critical vulnerability in the widely used security software.
Security researcher Chaotic Eclipse released a proof-of-concept (PoC) for ShieldCrash, a new zero-day vulnerability in Microsoft Defender that bypasses the recent patch for CVE-2026-69414 (ShieldBreak). This bypass allows for arbitrary file reads as SYSTEM on all supported Windows versions, indicating that Microsoft's initial fix was incomplete.
Security researcher Nightmare Eclipse disclosed three new zero-day exploits affecting products from Avast, CrowdStrike, and Nvidia. These exploits allow privilege escalation or impact shared memory, prompting vendors to issue advisories and patches.
A security researcher released a zero-day exploit, "FalconFlank," affecting CrowdStrike Falcon on Windows 11 and Windows Server, enabling attackers to gain SYSTEM privileges. The vulnerability abuses CrowdStrike Falcon's Office malicious macros remediation feature. CrowdStrike is investigating and advises customers to disable a specific Microsoft Office Windows policy setting.
A security researcher released a proof-of-concept (PoC) for "FalconFlank," a zero-day privilege escalation vulnerability affecting CrowdStrike Falcon. This vulnerability abuses malicious macro remediation in the Falcon Sensor, allowing for privilege escalation on Windows 11 and Windows Server 2025 systems.
Security researcher Nightmare Eclipse released a proof-of-concept exploit, dubbed "HardBreacher," targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. Kaspersky stated that the underlying issue has been resolved via an automatic update, or users can trigger a database update manually. This exploit highlights ongoing concerns about endpoint security product vulnerabilities and the impact of public zero-day disclosures.