discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

A researcher released a Microsoft Defender zero-day that can spawn a SYSTEM-level command prompt on fully patched Windows 10 and 11 devices.

By Lawrence Abrams·Jun 9·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
Image: bleepingcomputer.com

Nightmare Eclipse says the new 'RoguePlanet' bug affects fully updated Windows systems and can sometimes yield SYSTEM privileges through a Defender race condition. ThreatLocker says it reproduced the issue, while Microsoft has not yet publicly commented.

Why it matters

This is a high-impact Windows privilege-escalation flaw because SYSTEM access is effectively full control of a machine. Even if exploitation is unreliable, a working proof of concept against patched systems raises the risk for defenders and incident responders.

A researcher found a Windows bug that can sometimes open a powerful command window as the boss account, called SYSTEM. It is like finding a spare key that can open the whole building, even after the locks were changed.

Analysis

What happened

A security researcher calling themselves Nightmare Eclipse published a new Microsoft Defender zero-day exploit named RoguePlanet. The article says it affects fully patched Windows 10 and Windows 11 systems and can spawn a command prompt with SYSTEM privileges when the race condition succeeds.

How it works

According to the researcher, the exploit targets Microsoft Defender and was tested against Windows 11 official and Canary builds, plus Windows 10 systems with June 2026 updates installed. Nightmare Eclipse says the issue is a race condition, which makes exploitation inconsistent: it may fail often, but it can also succeed repeatedly on some machines.

The researcher says RoguePlanet started as a remote code execution path involving Defender handling files hosted on remote SMB shares. In that earlier form, the attack required convincing a victim to open a .vhd(x) file on a remote SMB server. The researcher also says another scenario could have led to remote code execution if symlink evaluation settings were enabled. They claim Microsoft later hardened Defender in mid-May by patching an internal mpengine!SysIO* API, which blocked junction-based attacks and forced a rewrite of the exploit.

Why defenders care

ThreatLocker told BleepingComputer it reproduced the flaw against fully patched Windows 11 with KB5094126 installed. The company said application allowlisting can stop the exploit from running, which could provide a useful layer of defense.

The story also sits inside an ongoing conflict between the researcher and Microsoft over disclosure and bug bounty practices. The article says Nightmare Eclipse has already released several other Windows zero-days, including BlueHammer, RedSun, GreenPlasma, and YellowKey. Microsoft has previously warned about malicious activity causing real harm, and the researcher says earlier GitHub and GitLab repositories were removed, prompting a move to a self-hosted code site.

BleepingComputer says it contacted Microsoft for comment and will update the story if it gets a response.

Key points

  • Nightmare Eclipse published a new Microsoft Defender zero-day called RoguePlanet.
  • The article says it can spawn a command prompt with SYSTEM privileges on patched Windows 10 and 11 machines.
  • ThreatLocker said it reproduced the flaw and confirmed it on fully patched Windows 11 with KB5094126.
  • The researcher says Microsoft previously hardened Defender, forcing the exploit to be rewritten.
  • Application allowlisting is presented as a possible mitigation layer.
The Upside

If the exploit is quickly patched or blocked by defenses like application allowlisting, organizations can reduce the chance of real-world abuse. Public proof can also push Microsoft and security teams to harden Defender behavior faster.

The Downside

The exploit works on fully patched Windows 10 and 11 systems, so defenders cannot assume normal updates are enough. Even if the race condition is unreliable, a successful run gives attackers SYSTEM privileges, which can lead to full compromise.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechmicrosoftwindowszero-day

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 9, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechmicrosoftwindowszero-day

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.