Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 5 sources · 9 days · First seen · Last updated
Nightmare Eclipse antivirus zero-day exploits
Overview
Security researcher Chaotic Eclipse, also known as Nightmare Eclipse, has released a series of zero-day proof-of-concept exploits targeting major antivirus and security software.
On September 1, the researcher released ‘HardBreacher’, which targets Kaspersky Endpoint Security to allow privilege escalation on Windows 11 systems, and ‘PrettyPrague’, which targets Avast Antivirus to dump the Windows SAM database and gain a SYSTEM-level shell. Kaspersky reported that it had already addressed the HardBreacher vulnerability.
On September 9, the researcher released ‘ShieldCrash’, a zero-day exploit targeting Microsoft Defender. This exploit reportedly acts as a bypass for a previous vulnerability, ‘ShieldBreak’ (CVE-2026-69414), which Microsoft had attempted to patch in its September 2026 security updates. The current proof of concept demonstrates arbitrary file reading with SYSTEM privileges on Windows 10, Windows 11, and Windows Server.
Entities
Nightmare Eclipse · Kaspersky · Microsoft · Gen Digital · Avast
Timeline
-
2 days ago
[TECHNOLOGY] 3 sourcesMicrosoft Defender zero-day exploit bypasses recent security patchesResearcher Nightmare Eclipse has released ‘ShieldCrash,’ a zero-day exploit that bypasses Microsoft Defender patches to allow privilege escalation on updated Windows systems.
-
10 days ago
[TECHNOLOGY] 2 sourcesChaotic Eclipse releases zero-day exploits for Kaspersky and AvastResearcher Chaotic Eclipse has released two new zero-day exploits, ‘HardBreacher’ and ‘PrettyPrague’, targeting Kaspersky Endpoint Security and Avast Antivirus respectively.
Sources
cybernoz.com · redeszone.net · rockyharbour.ca · securityaffairs.com · softzone.es