LIVE · cybersecurity feed
Live wire
US sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

zeroday.news ·

A zero-day elevation-of-privilege vulnerability, tracked as CVE-2026-69414 and dubbed "ShieldBreak," has been discovered in the Microsoft Malware Protection Engine, which is integral to Microsoft Defender. This flaw allows a local attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems.

A public proof-of-concept (PoC) demonstrating the vulnerability was released on August 12, 2026. Microsoft acknowledged the issue and assigned the CVE identifier on August 14, 2026, but a security update or patch is not yet available.

ShieldBreak exploits how Microsoft Defender processes files during cloud-file hydration. The attack vector involves a user-mode callback that interferes with file data received by Defender through the Cloud Filter API (CFAPI). By manipulating Windows filesystem and Object Manager mechanisms, an attacker can influence which files Defender ultimately scans. This manipulation allows attacker-controlled content to be processed by Defender's elevated privileges, leading to code execution as NT AUTHORITY\SYSTEM.

The publicly available PoC has been confirmed to work on Windows 11 25H2 and Windows Server 2025. This vulnerability follows closely on the heels of another Microsoft Defender privilege-escalation flaw, CVE-2026-50656, known as RoguePlanet, for which Microsoft recently released a fix.

Given the absence of an official patch from Microsoft, organizations are currently exposed to this critical vulnerability. Cybersecurity experts emphasize the urgency of implementing temporary mitigations to reduce risk while awaiting a permanent fix. These mitigations typically involve restricting user privileges and monitoring for suspicious activity that might indicate an attempted exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, which mandates federal civilian executive branch agencies to address known exploited vulnerabilities within a specific timeframe. While the directive's exact requirements for this specific zero-day are not detailed, such critical vulnerabilities typically fall under its purview, often requiring remediation within 14 days of identification.

Security researchers have provided detection methods for ShieldBreak, including specific queries for vulnerability management platforms to identify affected assets within an environment. These tools can help organizations gain visibility into their exposure and verify the effectiveness of any applied mitigations.

Until Microsoft releases an official security update, organizations are advised to implement available workarounds and monitor their systems closely. The potential for a low-privileged local attacker to gain SYSTEM-level access underscores the severity of ShieldBreak and the immediate need for protective measures.

vulnerabilitymalwarezero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

vulnerability

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

security

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'

security

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

Glassbox dev admits he had some help from Claude to build locally running tool