legal action

Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Winsage
August 12, 2026
A security researcher named Nightmare Eclipse has discovered a vulnerability in Windows, called ShieldBreak, which allows hackers to gain system-wide access to users' devices and sensitive data by exploiting a flaw in Windows Defender. The vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. A proof-of-concept exploit has been provided, requiring users to run a Windows application to trigger the vulnerability. Security researcher Will Dormann confirmed that Windows Defender must be enabled for the exploit to work. Microsoft has not yet released a patch for ShieldBreak, which is classified as a zero-day vulnerability. This discovery follows previous vulnerabilities disclosed by Nightmare Eclipse, including RoguePlanet, for which Microsoft issued an inadequate patch. The situation has heightened tensions between the researcher and Microsoft regarding the handling of bug reports, especially after Microsoft threatened legal action against researchers disclosing zero-days outside established protocols. The disclosure of ShieldBreak occurred shortly after Microsoft's monthly security patch releases, which have been increasing in number.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
July 30, 2026
Australia’s eSafety Commissioner, Julie Inman Grant, has filed a lawsuit against the encrypted messaging app Telegram for allegedly failing to detect and remove pro-terrorist and extremist content. This legal action follows a year-long investigation and is the first enforcement of online codes regarding unlawful material established a year ago. The lawsuit details multiple violations of the Online Safety Act 2021, including the failure to remove posts related to the Christchurch mosque attack and the Buffalo mass shooting, despite user reports. Telegram has claimed to have blocked over 150,000 terrorist-related communities and removed over 200 million pieces of terrorist content. If the lawsuit is successful, it could lead to penalties up to A.6 million and potentially a ban on the app in Australia.
AppWizard
July 30, 2026
Australia's eSafety watchdog has initiated legal proceedings against the messaging platform Telegram for allegedly failing to adequately remove extremist content, including footage related to mass shootings in Buffalo and Christchurch, as well as material linked to the Islamic State. The platform, with a user base of approximately 1 billion, could face fines of up to 54.6 million Australian dollars (around 38 million USD) if found guilty. eSafety Commissioner Julie Inman Grant emphasized that the content in question is tied to severe acts of extremist violence and remained accessible despite Telegram being notified of its existence. Following recent tragedies, Telegram channels have surfaced that celebrate attackers and circulate videos of their acts. Telegram has denied the allegations, claiming to block terrorist-related content and reporting the removal of over 150,000 terrorist-related communities this year. However, Inman Grant raised concerns about the platform's compliance and responsiveness to regulatory actions.
Winsage
July 27, 2026
On July 22, Microsoft announced the KMS Hardware-Secured requirement, linking Windows volume activation servers to a TPM chip. This initiative is aimed at organizations using Key Management Service (KMS) servers to enhance security by ensuring that KMS hosts verify their identity and integrity through the TPM before activating Windows machines. The motivation behind this requirement is to prevent unauthorized activation methods that exploit fake KMS servers. Organizations are advised to ensure their KMS hosts are certified and that TPM is enabled. The KMS Hardware-Secured measures do not target individual users with pirated copies of Windows, as most current piracy methods do not involve KMS servers. Microsoft has not pursued legal action against minor piracy instances, focusing instead on maintaining user engagement through subscriptions and services.
AppWizard
July 17, 2026
Epic Games and Google have withdrawn their proposed settlement regarding app distribution on Android, which included a program for registered app stores. This decision allows Google to permit third-party app stores on its platform. The legal dispute began when Epic accused Google of monopolizing Android app distribution. Despite multiple victories for Epic, the companies attempted a settlement that included new billing options and reduced fees, but concerns about sideloading apps led to its abandonment. Google plans to invite other app stores starting July 22 in the United States.
AppWizard
July 9, 2026
MindsEye, an action game from Build a Rocket Boy, is set to have a playtest at the studio's Edinburgh headquarters, inviting community members and covering their travel costs. This comes after significant layoffs that affected over 400 employees, leading to protests organized by the Independent Workers Union of Great Britain, which criticizes the studio for spending on the playtest while having recently laid off staff. The union also alleges the studio has engaged in questionable practices, including employee surveillance. The playtest is seen as a strategy to regain favor with fans amid concerns about the studio's management and treatment of its workforce.
Search