Researcher

Winsage
August 27, 2026
Researcher Dominik Reichel has identified a new malware implant called SLEEPWALKER, which is disguised as an agent from ESET. SLEEPWALKER is unique because it does not contain malicious code and remains dormant until it receives specific network signals to activate. It appears to be designed for targeted attacks, likely orchestrated by nation-states. Although it was submitted to VirusTotal last year, it has not been linked to any active campaigns or confirmed victims. The origins of SLEEPWALKER are unknown, and its code is described as somewhat "rough around the edges," indicating it may still be in development.
Winsage
August 24, 2026
Malware researcher Dominik Reichel has discovered a sophisticated Windows backdoor named Sleepwalker, which remains dormant in memory until activated by a specially crafted network packet. Sleepwalker uses a 23-instruction command language to execute tasks, including running code in memory and exfiltrating data. It activates through a proprietary activation packet that does not contain readable commands. The malware targets a VMware VMCI and disguises itself as Microsoft's dpapi.dll, mimicking its functions while redirecting calls to a non-existent file. Once it confirms its host process as ERAAgent.exe, it enters a dormant state to evade detection. Sleepwalker monitors for a specific pattern known as a magic packet to decrypt and interpret commands. Commands sent to it are encrypted with AES-256-CCM and must be read in a specific order. The backdoor includes functionalities for sending and concealing data, receiving tasks, and executing programs. Reichel has developed a toolkit to decode Sleepwalker’s bytecode and a mitigation guide for affected users. However, there are significant gaps in knowledge regarding the initial access method, victim identification, and the malware's operator.
AppWizard
August 22, 2026
A new free PC game on Steam has received a rating of 96 out of 100 based on nearly 1,000 user reviews, earning it an “Overwhelmingly Positive” designation. Out of 986 reviews, 965 are positive. The game's compatibility with the Steam Deck is currently listed as “Unknown.” Developed by Zzangdol Games and published by Jungle Game Lab, the game is titled "No Results Found," which involves players investigating a case related to the Church of the Nine-Tentacled Octopus after a tragic incident where 227 church affiliates drowned. The game has been praised for its immersive storytelling and engaging deduction mechanics, though some reviews mention its complexity and the use of AI in development.
AppWizard
August 18, 2026
A graduate student from the University of Tokyo, Misaki Katayama, has been leading two-day workshops since 2023 that allow fourth- to sixth-grade elementary school students to explore the historical landscapes of Hiroshima and Nagasaki before the atomic bombings of August 1945. Using Minecraft, students reconstruct the cities with the help of historical maps, photographs, and video footage, fostering engagement, creativity, and reflection on the impact of nuclear warfare.
Winsage
August 13, 2026
Security researcher Nightmare Eclipse has released a zero-day exploit named ShieldBreak that allows privilege escalation on Windows by targeting a vulnerability in Microsoft Defender. This exploit, designated as CVE-2026-50656, is categorized as a race condition vulnerability and affects the latest versions of Windows 11 and Windows Server 2025, with potential impacts on Windows 10. The exploit was disclosed on June 9, 2026, and Microsoft acknowledged the issue on June 16, rolling out fixes by July 9. The mechanics of ShieldBreak involve manipulating Defender’s scan path and executing a scheduled task to gain System-level privileges. Experts have noted differences between ShieldBreak and the previously known RoguePlanet exploit, emphasizing that ShieldBreak requires Defender to be active to function.
Winsage
August 13, 2026
A vulnerability in Microsoft Defender, named ShieldBreak, has been revealed by security researcher Nightmare Eclipse, allowing malicious actors to gain complete system-level access to a user's device. Microsoft has previously warned against public disclosure of vulnerabilities and suggested potential legal repercussions for researchers who do so outside its protocols. Users of Microsoft Defender are advised to remain vigilant regarding this vulnerability.
Winsage
August 12, 2026
A security researcher named Nightmare Eclipse has discovered a vulnerability in Windows, called ShieldBreak, which allows hackers to gain system-wide access to users' devices and sensitive data by exploiting a flaw in Windows Defender. The vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. A proof-of-concept exploit has been provided, requiring users to run a Windows application to trigger the vulnerability. Security researcher Will Dormann confirmed that Windows Defender must be enabled for the exploit to work. Microsoft has not yet released a patch for ShieldBreak, which is classified as a zero-day vulnerability. This discovery follows previous vulnerabilities disclosed by Nightmare Eclipse, including RoguePlanet, for which Microsoft issued an inadequate patch. The situation has heightened tensions between the researcher and Microsoft regarding the handling of bug reports, especially after Microsoft threatened legal action against researchers disclosing zero-days outside established protocols. The disclosure of ShieldBreak occurred shortly after Microsoft's monthly security patch releases, which have been increasing in number.
Search