iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games Sarvam AI Raises $234M Led by HCLTech, Becomes India's Newest Unicorn India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games Sarvam AI Raises $234M Led by HCLTech, Becomes India's Newest Unicorn
Home ›› Technology ›› Cybersecurity ›› Microsoft Defender Zero-Day Exploit Threatens System Security

Microsoft Defender Zero-Day Exploit Threatens System Security

A newly disclosed zero-day vulnerability in Microsoft Defender, named 'RoguePlanet', allows attackers to gain SYSTEM privileges on Windows 10 and 11. Security researcher Chaotic Eclipse revealed this exploit, highlighting ongoing tensions with Microsoft over vulnerability disclosures.

iG
iGEN Editorial
June 10, 2026
Microsoft Defender Zero-Day Exploit Threatens System Security

A newly disclosed zero-day vulnerability in Microsoft Defender, named "RoguePlanet", poses a significant threat to system security by allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11 devices. This vulnerability was revealed by the security researcher known as Chaotic Eclipse, who has a history of publicly disclosing such exploits due to dissatisfaction with Microsoft's handling of vulnerability reports.

RoguePlanet Exploit Details

The "RoguePlanet" exploit is described as a "race condition vulnerability". According to TechRadar, this type of exploit can be inconsistent, with success rates varying across different machines. ThreatLocker, a cybersecurity firm, confirmed the viability of the exploit and demonstrated its functionality. Danny Jenkins, CEO of ThreatLocker, noted that organizations using application allowlisting can effectively prevent the exploit from executing, providing a crucial layer of protection.

Chaotic Eclipse's Disclosure History

Chaotic Eclipse has previously disclosed six other zero-day vulnerabilities, including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma. The researcher has expressed frustration with Microsoft's response to these disclosures, leading to a series of public releases. In the latest Patch Tuesday update, Microsoft addressed two of these vulnerabilities: GreenPlasma and YellowKey.

Implications for Enterprises

The disclosure of the RoguePlanet exploit underscores the importance of robust cybersecurity measures for enterprises. Organizations must ensure that their systems are protected against such vulnerabilities by implementing comprehensive security protocols, including application allowlisting and regular updates. The ongoing feud between Chaotic Eclipse and Microsoft highlights the challenges in vulnerability management and the need for transparent communication between researchers and software vendors.

Vulnerability Status
BlueHammer Disclosed
RedSun Disclosed
UnDefend Disclosed
YellowKey Patched
GreenPlasma Patched
MiniPlasma Disclosed
RoguePlanet Disclosed

The cybersecurity landscape continues to evolve, and enterprises must stay vigilant to protect their systems from emerging threats. The RoguePlanet exploit serves as a reminder of the potential risks posed by zero-day vulnerabilities and the critical need for proactive security measures.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Linux Kernel Vulnerability: A Single Character Threat Technology

Linux Kernel Vulnerability: A Single Character Threat

A logic inversion bug in the Linux kernel, identified as CVE-2026-23111, allows privilege escalation, affecting major distributions like Debian, Ubuntu, and RHEL. The vulnerability highlights challenges in managing AI-driven bug reports.

June 9, 2026
AI's Role in Accelerating Cyber Vulnerabilities Technology

AI's Role in Accelerating Cyber Vulnerabilities

AI is significantly reducing the time it takes for adversaries to exploit vulnerabilities, challenging traditional cybersecurity defenses. Organizations must shift focus from prevention to resilience to maintain operations.

June 10, 2026
Microsoft Disables 73 GitHub Repos After Malware Breach Technology

Microsoft Disables 73 GitHub Repos After Malware Breach

Microsoft has disabled 73 GitHub repositories after hackers used stolen credentials to plant malware. The breach affected multiple organizations, including Azure, and led to significant disruptions. Microsoft is investigating and has notified affected customers.

June 9, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026