- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,246
The famous hacker has released a new exploit called RoguePlanet.

The confrontation of the researcher under the nickname Nightmare Eclipse with Microsoft led to the next publication of a dangerous vulnerability of Windows: an exploit appeared on the network RoguePlanet for Microsoft Defender, which allows you to get maximum system rights even on a fully updated computer with Windows 10 or Windows 11.
The vulnerability is based on the state of the race – a situation where two processes simultaneously turn to one resource, and the attacker manages to intervene at this moment. As a result of a successful attack on the screen, a command line with the privileges of SYSTEM, the highest level of access in Windows, opens. In addition to GitHub, Nightmare Eclipse published the working code of the exploit and in its own repository, citing the fact that Microsoft has repeatedly removed its materials with GitHub and GitLab.
ThreatLocker has confirmed the operability of the exploit on fully updated Windows 11 systems with an installed update KB5094126 and even published a video with a demonstration. The researcher himself stipulates that the result is unstable: on some machines it was possible to achieve one hundred percent work, others worked worse.
Initially, the vulnerability was conceived as a tool for remote code execution through the processing of Defender files on remote SMB servers. However, in mid-May, Microsoft unnoticed the appropriate mechanism of the defender, blocking one of the key vectors of the attack. After that, Nightmare Eclipse reworked the exploit, but admitted that the possibility of remote execution of the code is still in question.
The publication has become part of a protracted conflict between researcher and Microsoft because of the policy of payments for the vulnerabilities found. In recent months, Nightmare Eclipse has uncovered several zero-day vulnerabilities, including BlueHammer, RedSun, GreenPlasma and YellowKey. The last two Microsoft closed as part of the June Patch Tuesday – the same day RoguePlanet appeared. The company previously warned that it was ready to involve law enforcement agencies in the event of “harmful activities” that could harm its customers. However, later smoothed out corners after resonance in the community.
ThreatLocker noted that organizations using approved applists can block RoguePlanet execution. There was no official correction from Microsoft at the time of publication.

The confrontation of the researcher under the nickname Nightmare Eclipse with Microsoft led to the next publication of a dangerous vulnerability of Windows: an exploit appeared on the network RoguePlanet for Microsoft Defender, which allows you to get maximum system rights even on a fully updated computer with Windows 10 or Windows 11.
The vulnerability is based on the state of the race – a situation where two processes simultaneously turn to one resource, and the attacker manages to intervene at this moment. As a result of a successful attack on the screen, a command line with the privileges of SYSTEM, the highest level of access in Windows, opens. In addition to GitHub, Nightmare Eclipse published the working code of the exploit and in its own repository, citing the fact that Microsoft has repeatedly removed its materials with GitHub and GitLab.
ThreatLocker has confirmed the operability of the exploit on fully updated Windows 11 systems with an installed update KB5094126 and even published a video with a demonstration. The researcher himself stipulates that the result is unstable: on some machines it was possible to achieve one hundred percent work, others worked worse.
Initially, the vulnerability was conceived as a tool for remote code execution through the processing of Defender files on remote SMB servers. However, in mid-May, Microsoft unnoticed the appropriate mechanism of the defender, blocking one of the key vectors of the attack. After that, Nightmare Eclipse reworked the exploit, but admitted that the possibility of remote execution of the code is still in question.
The publication has become part of a protracted conflict between researcher and Microsoft because of the policy of payments for the vulnerabilities found. In recent months, Nightmare Eclipse has uncovered several zero-day vulnerabilities, including BlueHammer, RedSun, GreenPlasma and YellowKey. The last two Microsoft closed as part of the June Patch Tuesday – the same day RoguePlanet appeared. The company previously warned that it was ready to involve law enforcement agencies in the event of “harmful activities” that could harm its customers. However, later smoothed out corners after resonance in the community.
ThreatLocker noted that organizations using approved applists can block RoguePlanet execution. There was no official correction from Microsoft at the time of publication.