Windows Defender Zero-Day Vulnerability Has No Patch

Windows Defender zero-day vulnerability

A Windows Defender zero-day vulnerability disclosed on August 12, 2026 lets a low-privileged local attacker bypass Microsoft’s own patch for an earlier Defender flaw and escalate straight to SYSTEM. Tracked as CVE-2026-69414 and nicknamed ShieldBreak, the flaw still has no fix ten days after Microsoft assigned the CVE. Any Windows endpoint running default Defender is…

Read More

Windows IKE RCE: Patched in April, Exploited Now

CVE-2026-33824 Windows IKE RCE is now actively exploited despite an April patch. CVSS 9.8, no auth needed. See who's affected and what to check today.

CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…

Read More

CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit

CVE-2026-68820 WinSock zero-day

The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More

Nightmare Eclipse Windows Zero-Day Trilogy

Nightmare Eclipse Windows zero-day

The Nightmare Eclipse Windows zero-day trilogy has moved from proof-of-concept code on GitHub to a confirmed, real-world intrusion: Huntress found BlueHammer, RedSun, and UnDefend deployed together in one attack chain that started with a compromised FortiGate VPN appliance. What Happened A researcher operating under the handle “Nightmare Eclipse” (also seen as “Chaotic Eclipse”) has published…

Read More