Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026

    Microsoft patches LegacyHive Windows zero-day vulnerability

    August 15, 2026

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    August 15, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Microsoft patches LegacyHive Windows zero-day vulnerability
    News

    Microsoft patches LegacyHive Windows zero-day vulnerability

    adminBy adminAugust 15, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Windows

    Microsoft has released security patches to address a Windows zero-day vulnerability known as “LegacyHive,” disclosed after the July 2026 Patch Tuesday.

    The security flaw was disclosed by a security researcher who uses the “Nightmare Eclipse” handle in protest of Microsoft’s bug bounty and vulnerability disclosure practices.

    Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service.

    image

    However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.

    “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.

    Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse’s exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.

    One day after the PoC was released, cybersecurity expert Kevin Beaumont also published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked.

    Official LegacyHive patches available

    Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. However, it has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead tagging it as reported by an anonymous researcher.

    The company says that LegacyHive stems from improper link resolution before file access (‘link following’) in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges.

    “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive,” Microsoft says. “Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required.”

    ACROS Security, the company behind the 0Patch cybersecurity platform, also released free unofficial LegacyHive patches on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later.

    Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and other Windows components.

    Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, and the RoguePlanet vulnerability in July, but the other zero-days are still awaiting an official patch.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAkira hackers disable EDR with Safe Mode, steal data but fail to encrypt
    Next Article AI ‘watermark removers’ flood the web. Almost none can prove they work.
    admin
    • Website

    Related Posts

    News

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026
    News

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    August 15, 2026
    News

    Ukraine shuts down 94 fraudulent call centers, seize millions in cash

    August 15, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026

    Microsoft patches LegacyHive Windows zero-day vulnerability

    August 15, 2026

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    August 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.