A security researcher just dropped a Windows Defender zero-day in public, and the backstory is messier than the bug itself.
A researcher who goes by Nightmare Eclipse has publicly disclosed a new flaw in Windows Defender called ShieldBreak. The bug lets an attacker use the built-in antivirus tool itself to escalate privileges on a Windows machine. Nightmare Eclipse published the details despite Microsoft having previously threatened legal action against them. The disclosure turns what was a private standoff between researcher and vendor into a public one.
Security tools like Defender run with deep system access, which is exactly what makes a flaw inside them so useful to an attacker chasing privilege escalation. That Microsoft reportedly reached for legal threats rather than a fix or a bounty arguably explains why this ended up as a public zero-day instead of a quiet patch: pressuring a researcher does not make a vulnerability disappear, it just removes their incentive to wait.
Vendors have learned this lesson before: squeeze a researcher hard enough, and the disclosure goes public instead of staying private.