vulnerability

Winsage
August 14, 2026
Researchers from the University of Birmingham and Durham University discovered a vulnerability in consumer DDR4 and DDR5 memory chips, termed "Download more RAM," which allows attackers to misreport memory configuration, potentially doubling the perceived RAM. This manipulation enables unauthorized access to memory allocations, bypassing Windows' Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI), and disabling antivirus software. The vulnerability affects major manufacturers like Corsair, G.Skill, and ADATA, which collectively hold over 55% of the high-performance memory market. Microsoft has patched the vulnerability, cataloged as CVE-2026-23670, with a medium severity score of 5.7/10, in the April 2026 Patch Tuesday update. Corsair has introduced a feature to enable write protection on their memory modules, and other tools are available for additional protection.
Tech Optimizer
August 14, 2026
Researchers have identified a significant vulnerability in consumer DDR4 and DDR5 memory modules, known as the “Download more RAM” flaw, which allows attackers to bypass advanced Windows security features, including Virtualization-Based Security (VBS) and Hypervisor Code Integrity (HVCI). This vulnerability enables the manipulation of configuration reports from RAM, misleading the system about its actual memory capacity, which can disable antivirus protections and allow the reintroduction of outdated drivers. The exploit can be executed via a single-click script, leading to security failures. Microsoft has released a patch for CVE‑2026‑23670 to enhance memory write protection against such exploits.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Winsage
August 13, 2026
Security researcher Nightmare Eclipse has released a zero-day exploit named ShieldBreak that allows privilege escalation on Windows by targeting a vulnerability in Microsoft Defender. This exploit, designated as CVE-2026-50656, is categorized as a race condition vulnerability and affects the latest versions of Windows 11 and Windows Server 2025, with potential impacts on Windows 10. The exploit was disclosed on June 9, 2026, and Microsoft acknowledged the issue on June 16, rolling out fixes by July 9. The mechanics of ShieldBreak involve manipulating Defender’s scan path and executing a scheduled task to gain System-level privileges. Experts have noted differences between ShieldBreak and the previously known RoguePlanet exploit, emphasizing that ShieldBreak requires Defender to be active to function.
Winsage
August 13, 2026
A vulnerability in Microsoft Defender, named ShieldBreak, has been revealed by security researcher Nightmare Eclipse, allowing malicious actors to gain complete system-level access to a user's device. Microsoft has previously warned against public disclosure of vulnerabilities and suggested potential legal repercussions for researchers who do so outside its protocols. Users of Microsoft Defender are advised to remain vigilant regarding this vulnerability.
Winsage
August 13, 2026
The upcoming Patch Tuesday is scheduled for September 8th, 2026, during which Microsoft will address over 200 vulnerabilities across Windows platforms, including Windows 10, Windows 11, and Windows Server. Windows 10 users in the Extended Security Updates (ESU) program will receive updates until October 2027. Among the vulnerabilities, CVE-2026-68820 allows attackers to gain elevated privileges through the Windows auxiliary function driver for Winsock. Microsoft has identified 18 vulnerabilities as critical, including CVE-2026-62878, an RCE vulnerability in the Windows DNS server that can lead to a buffer overflow and code execution without user interaction. Another critical issue is CVE-2026-62893, a UAF vulnerability in the TFTP server of Windows Deployment Services, which allows code injection through UDP port 69. Additionally, CVE-2026-62815, an RCE vulnerability in Quick UDP Internet Connections (QUIC), permits code execution without user interaction, while CVE-2026-59124, although high risk, is not classified as critical due to the HPC Pack not being enabled by default.
Winsage
August 12, 2026
Microsoft's August Patch Tuesday update addressed 421 vulnerabilities across various products, including multiple versions of Windows (11 25H2/24H2, 11 23H2, and 10). A critical zero-day flaw, the "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability," allows attackers with lower-level access to gain system privileges without user interaction. Additionally, the update addresses two other zero-day flaws, including the "Windows User Profile Service Elevation of Privilege Vulnerability," which has not yet been exploited but was publicly disclosed. The update is mandatory and should automatically install on supported PCs, with users encouraged to verify its application. The update also includes minor improvements to Windows features, such as enhancements to File Explorer, Windows Hello, Voice Access, and touchpad controls.
Winsage
August 12, 2026
A security researcher named Nightmare Eclipse has discovered a vulnerability in Windows, called ShieldBreak, which allows hackers to gain system-wide access to users' devices and sensitive data by exploiting a flaw in Windows Defender. The vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. A proof-of-concept exploit has been provided, requiring users to run a Windows application to trigger the vulnerability. Security researcher Will Dormann confirmed that Windows Defender must be enabled for the exploit to work. Microsoft has not yet released a patch for ShieldBreak, which is classified as a zero-day vulnerability. This discovery follows previous vulnerabilities disclosed by Nightmare Eclipse, including RoguePlanet, for which Microsoft issued an inadequate patch. The situation has heightened tensions between the researcher and Microsoft regarding the handling of bug reports, especially after Microsoft threatened legal action against researchers disclosing zero-days outside established protocols. The disclosure of ShieldBreak occurred shortly after Microsoft's monthly security patch releases, which have been increasing in number.
Search