A cybersecurity researcher has discovered a potential bypass for a recently patched vulnerability in Microsoft Defender, allowing attackers to gain system-level control if they can achieve any level of access. This workaround was made public just weeks after Microsoft issued a security patch for the critical hole. The researcher, known as Nightmare Eclipse, has a history of identifying vulnerabilities in Microsoft's security products and has been in a long-standing battle with the company's security team. Microsoft has acknowledged the reported vulnerability and is currently investigating its validity1. The ability to bypass the patch poses a significant risk to systems running Microsoft Defender, as it could enable attackers to escalate their privileges and carry out more damaging attacks. This development matters to security practitioners because it highlights the ongoing cat-and-mouse game between vulnerability researchers and software vendors, and the need for continuous monitoring and assessment of security controls.