VYPR
researchPublished Aug 31, 2026· 2 sources

Nightmare Eclipse Releases 'HardBreacher' Exploit for Kaspersky Endpoint Security

A researcher known as Nightmare Eclipse has released a privilege escalation exploit targeting Kaspersky Endpoint Security, dubbed 'HardBreacher'.

A threat actor operating under the moniker Nightmare Eclipse has publicly released a new exploit targeting a vulnerability in Kaspersky's Endpoint Security product. The exploit, named "HardBreacher," allows for privilege escalation, enabling an attacker to gain elevated system access.

Nightmare Eclipse, also known as Chaotic Eclipse, has been prolific in releasing proof-of-concept (PoC) exploits for various vulnerabilities in recent months, with a particular focus on Windows and Microsoft Defender flaws. This activity reportedly stems from frustration with Microsoft's handling of vulnerability disclosures. While many of these exploits have remained in the PoC stage, some have been observed being used in the wild by malicious actors.

The "HardBreacher" exploit specifically targets a privilege escalation vulnerability within Kaspersky Endpoint Security. The researcher noted that the exploit's code is "not in the best shape" but is functional, indicating a rapid development and release cycle. The primary concern is the potential for significant system compromise if the exploit is successful.

According to the researcher, successful exploitation can lead to the Kaspersky product "completely losing it" when the UI process is taken over. This can result in the product ceasing to function correctly, unauthorized access to files, and a general destabilization of the entire operating system, turning it into a "hot mess."

Kaspersky has acknowledged the vulnerability and confirmed that a fix has already been deployed. The company stated that the corresponding patch is delivered through an automatic update mechanism. Users can also manually trigger a database update to ensure their systems are protected.

This release follows other recent PoC exploits from Nightmare Eclipse, including "ShieldBreak," which facilitates spawning a shell with System privileges, and "LegacyHive," another privilege escalation tool. The consistent release of such exploits highlights the ongoing efforts by independent researchers and potentially malicious actors to uncover and weaponize zero-day vulnerabilities.

The active release of exploits, even in a rough state, underscores the dynamic nature of cybersecurity. It also serves as a reminder for organizations to maintain robust endpoint security solutions and to apply patches promptly, especially when vendors confirm vulnerabilities and release fixes.

The new article provides further details on the HardBreacher proof-of-concept, specifying its testing on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.0.0.504. It highlights the PoC's instability and the author's claim that a reboot was involved during testing, while also noting the potential impact of disrupting the security product's operation and altering security configurations.

Synthesized by Vypr AI