That Defender flaw Microsoft fixed in July? Someone just walked around the fix
Microsoft patched a Microsoft Defender flaw called RoguePlanet in July, tracked as CVE-2026-50656. It let a program already running on a PC promote itself to SYSTEM - the highest level of control Windows has. On August 11, right around this month's Patch Tuesday, the researcher behind the original bug published ShieldBreak: a working bypass of that fix, reaching the same result by an entirely different route.
The new technique interferes with Defender while it scans a file being pulled down from cloud storage, swapping the file's contents mid-scan so Defender itself ends up loading the attacker's code as a trusted Windows component. The researcher reports a 100% success rate on Windows 11 25H2 and Windows Server 2025, with Windows 10 said to be affected too. Defender has to be switched on for it to work. Microsoft says it is "actively investigating the validity and potential applicability of these claims." No patch yet, and no sign of anyone using it in real attacks.
For a home user, one word does most of the work in that description: local. Nobody can fire this at you across the internet. Something has to be running on your machine first - a cracked game, a fake update, an installer from a search ad - and ShieldBreak then turns that limited foothold into total ownership of the PC. So the answer isn't to disable Defender, which would be strictly worse. It's that the front door still matters more than the hallway.
Worth noting the same researcher's earlier Windows User Profile Service bug, CVE-2026-62832 or "LegacyHive", was finally patched in the August update - so installing this month's update is still the right move.
Tendvane can't close a hole Microsoft hasn't fixed yet. What it can do is confirm the August patches actually landed on your PC, and that Defender and BitLocker are still switched on, through its check-for-updates and security-posture checks.