Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
Home/CyberSecurity News/Windows Defender 0-Day “RoguePlanet” Grants Exploit Lets
CyberSecurity News

Windows Defender 0-Day “RoguePlanet” Grants Exploit Lets

Security researcher Nightmare Eclipse, also known by the aliases Chaotic Eclipse and Dead Eclipse, has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet. This exploit targets a...

Sarah simpson
Sarah simpson
June 10, 2026 3 Min Read
16 0

Security researcher Nightmare Eclipse, also known by the aliases Chaotic Eclipse and Dead Eclipse, has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet. This exploit targets a previously undisclosed race condition vulnerability found in Microsoft Windows Defender.

When successfully executed, the exploit spawns a command shell running under SYSTEM-level privileges, granting an attacker the highest possible access on a compromised Windows machine.

The release, posted to GitHub, arrives on Patch Tuesday, June 10, 2026, adding urgency to an already escalating series of Defender-targeting disclosures.

Windows Defender 0-Day Exploit “RoguePlanet”

RoguePlanet is a local privilege escalation (LPE) exploit that abuses a race condition within Microsoft Defender’s internal processing logic. A standard, unprivileged user can leverage the vulnerability to redirect a file operation performed by Defender, which runs as SYSTEM, in order to execute attacker-controlled code at the highest privilege level.

The exploit has been confirmed to work on fully patched Windows 10 and Windows 11 systems, including both the official stable and Canary Insider Preview channels, with the June 2026 patch applied.

Windows Server installations are also considered vulnerable, though the current PoC does not function in that environment because standard users cannot mount ISO images, a prerequisite of this specific exploit chain.

The underlying flaw is a Time-of-Check to Time-of-Use (TOCTOU) race condition, a class of vulnerability that Nightmare Eclipse previously exploited in the BlueHammer exploit (CVE-2026-33825) rated CVSS 7.8 (High) which was patched by Microsoft in April 2026.

In that earlier case, Defender’s file remediation engine performed privileged write operations without adequately locking down file path validation, enabling an attacker to insert NTFS junction points that redirected Defender’s SYSTEM-level writes into C:WindowsSystem32.

RoguePlanet employs a similar path-redirection strategy, demonstrating that Microsoft’s efforts to harden Defender against this class of attack remain incomplete.

RoguePlanet is the latest in a growing series of zero-day releases according to Nightmare Eclipse, which has now disclosed at least seven Defender-related exploits since early April 2026, including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.

This campaign is widely described by security researchers as a retaliatory effort following disputes with Microsoft over responsible disclosure and account terminations.

Huntress researchers have already documented real-world intrusions using earlier tooling from this researcher, with BlueHammer, RedSun, and the Defender-disruption tool UnDefend observed in live attack chains.

The success rate of RoguePlanet varies across environments. The researcher notes a 100% success rate on some machines, while the exploit struggled on others due to the inherent instability of race conditions.

The exploit does not work on Windows Server in its current form, though all Server versions are believed to be vulnerable to the same underlying flaw with a redesigned attack vector.

Microsoft has not yet issued a CVE or public advisory for RoguePlanet as of the time of publication. Given the active exploitation of earlier Nightmare Eclipse tooling in the wild, organizations running Windows 10 or Windows 11 endpoints should treat this disclosure as a high priority and monitor Microsoft’s Security Update Guide for an emergency patch.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

MagicAd Android Malware Floods Devices with Ads, B

Next Post

Anthropic Launches Claude Fable 5: First Released Model

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us