Breaking 09:10 Lionel Messi leads Inter Miami to Campeones Cup title with 100th goal 08:15 US prosecutors seek $61 million in assets linked to alleged Iranian oil revenue network 08:00 Trump says Iran wants a deal as he signals the war may be nearing its end 07:19 Morocco and Israel agree to upgrade diplomatic missions to full embassies 23:00 AI companies say businesses are capturing only a fraction of the technology’s potential 22:45 Morocco welcomes 24 U.S. Fulbright grantees for research and teaching in 2026-2027 22:15 UN puts artificial intelligence governance under the spotlight as global risks intensify 21:45 Most Americans see serious risks from advanced artificial intelligence, poll finds 21:21 Nvidia chief Jensen Huang rejects calls for new AI safety laws 19:30 Iran war drives US fuel costs higher, adding pressure on American households 19:15 Mistral AI joins Firefox Smart Window to expand choice in AI-powered browsing 18:05 OpenAI could approach a $1.2 trillion valuation in new funding round 16:50 China warns of a space arms race after US confirms orbital weapons 15:29 OpenAI, Anthropic and Google explore AI safety body as regulatory debate intensifies 14:14 Coca-Cola plans $10 billion US investment through 2030 13:45 Macklemore removed from Ed Sheeran’s US tour after “Free Palestine” remarks 13:12 Trump attacks Supreme Court after it blocks new mail voting restrictions 13:05 US household income reaches record high as poverty rate falls 12:45 White House backs industry-led solutions to AI risks 12:15 Mark Zuckerberg rejects calls to slow the race toward advanced AI 11:25 Meta expands plans to rely on its own AI chips 11:04 Elon Musk calls for rival AI companies to test each other’s models 10:59 Iran rejects talks with the United States as Trump signals openness to dialogue 10:19 Could AI destroy humanity? Trump dismisses the threat as a hoax 09:59 Israel Katz: Israeli Army Claims Readiness to 'Finish the Job' in Gaza 09:44 US announces new visa restrictions targeting South African officials

New Windows Defender zero-day enables system privileges escalation

Wednesday 10 June 2026 - 11:17
By: Dakir Madiha
New Windows Defender zero-day enables system privileges escalation

A new security flaw has emerged in Microsoft Defender shortly after the release of a major Patch Tuesday update cycle. The vulnerability allows attackers to gain SYSTEM-level privileges on fully updated Windows 10 and Windows 11 machines. The issue stems from a race condition inside Microsoft Defender, exposing systems even after recent security patches were applied.

The exploit, named RoguePlanet, was released as a proof-of-concept by a security researcher known as Nightmare Eclipse. The code demonstrates how local privilege escalation can be achieved on systems that have installed the June 2026 cumulative update KB5094126. Independent security analysis confirmed that the exploit functions as described and can be reproduced under real-world conditions.

ThreatLocker, a cybersecurity company, validated the findings after testing the exploit on updated Windows 11 systems. Its engineers confirmed that the attack can successfully elevate privileges under specific conditions, although execution depends on timing due to the race condition. The company noted that application allowlisting can block the exploit by restricting unauthorized execution paths on affected systems.

The researcher behind RoguePlanet stated that the exploit originally targeted remote code execution through Microsoft Defender handling of SMB share files, but later changes to Microsoft’s API forced a shift toward local privilege escalation. The researcher also described variable success rates across machines, indicating inconsistent exploitation depending on system behavior.

This disclosure is part of a broader campaign that has seen multiple zero-day releases targeting Windows components in recent months. Microsoft’s latest Patch Tuesday addressed more than 200 vulnerabilities, including several previously disclosed flaws. Among them was a privilege escalation issue in Defender that was already known to be actively exploited in the wild, highlighting continued pressure on the company’s security response cycle.

Microsoft initially reacted strongly to the wave of disclosures, suggesting possible legal action against individuals causing harm. The company later reversed its position and returned to a coordinated vulnerability disclosure framework. Despite this shift, the researcher continued publishing additional exploits through independent infrastructure.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.