NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session.
Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Splunk updated its "Windows Phantom DLL Created on Disk" analytic, which monitors suspicious phantom DLL creation or modification in Windows system paths, including ShieldBreak's phoneinfo.dll artifact.
Splunk published the "Windows Defender MpClient.dll Loaded by Non-Defender Process" anomaly detection to identify ShieldBreak-associated loading of the Defender client API library by non-Defender processes.
Splunk published the "Windows Defender Threat Detected on Kernel Object Path" analytic, which identifies Defender detection or remediation events involving paths containing \globalroot\ and is intended to detect ShieldBreak-related activity.
Splunk authored version 1.0 of its ShieldBreak dataset to support simulated Windows Defender exploitation detection, including Sysmon, Defender Operational, and Windows Security telemetry.
Microsoft reportedly patched RoguePlanet, tracked as CVE-2026-50656, which involved improper link resolution during Windows Defender remediation.
APT19 conducted a watering-hole attack on forbes.com to compromise targets.
NightmareEclipse released ShieldBreak, a proof-of-concept exploit claimed to bypass the RoguePlanet patch and obtain a SYSTEM shell by redirecting a privileged Defender write and abusing Windows Error Reporting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourcethreatlocker.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.