Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Summary: Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Nightmare Eclipse Releases ‘HardBreacher’ Zero-Day Targeting Kaspersky Endpoint Security

Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, has released another publicly available zero-day exploit, this time targeting Kaspersky Endpoint Security. The proof-of-concept, dubbed HardBreacher, exploits a privilege-escalation vulnerability that can interfere with the security product itself and potentially destabilize protections across the Windows operating system.

Kaspersky confirmed to SecurityWeek that the underlying vulnerability has already been fixed. The company says the correction is being distributed automatically through its update mechanism, while administrators can also trigger a database update manually to ensure systems receive the protection.

HardBreacher targets the security software itself

HardBreacher is particularly interesting because its target is not an ordinary Windows application. Endpoint security software operates with significant privileges because it needs to monitor processes, inspect files and control access to resources across the operating system.

According to Nightmare Eclipse, gaining control over the vulnerable Kaspersky user-interface process can cause the security product to behave unpredictably. The researcher says successful exploitation can interfere with Kaspersky’s operation and manipulate whether access to certain files is granted or blocked.

The researcher also acknowledged that the publicly released proof-of-concept is rough and was primarily constructed to demonstrate that exploitation is possible. SecurityWeek did not report evidence that HardBreacher is currently being exploited maliciously in the wild.

That distinction is important: publication of working exploit code increases risk, but it does not by itself establish that active attacks are taking place.

Endpoint security creates a powerful attack surface

The vulnerability highlights an uncomfortable property of security products. Antivirus and endpoint protection platforms need unusually deep access to the systems they defend, which means vulnerabilities inside those products can sometimes provide attackers with powerful opportunities for privilege escalation.

Security tools may run privileged services, monitor filesystem operations, inspect processes and interact with operating-system components that ordinary applications cannot access. An attacker who finds a way to manipulate those trusted components may therefore be able to turn a defensive mechanism into part of an exploitation chain.

HardBreacher appears to demonstrate that type of problem. Rather than simply disabling antivirus protection from the outside, the exploit manipulates behavior inside the endpoint security product itself.

Kaspersky says the vulnerability is already patched

Kaspersky told SecurityWeek that it investigated the issue and has resolved the underlying vulnerability. The fix is distributed through an automatic update, meaning properly configured Kaspersky Endpoint Security installations should receive it without requiring a conventional application upgrade. Administrators can also initiate the relevant update manually.

That makes updating particularly important now that proof-of-concept code is publicly available. Once researchers publish an exploit, other security researchers and threat actors can analyze the technique, improve reliability or adapt portions of it for different attack chains.

There is currently no indication in the report that attackers have done so with HardBreacher, but Nightmare Eclipse’s previous disclosures demonstrate that public PoCs do not always remain purely academic.

Nightmare Eclipse has released several Windows zero-days

HardBreacher is the latest in a growing series of vulnerability disclosures from Nightmare Eclipse. The researcher has published proof-of-concept exploits for numerous security flaws during 2026, particularly vulnerabilities involving Windows and Microsoft Defender.

Among the recent releases is ShieldBreak, an exploit capable of spawning a shell with SYSTEM privileges, as well as LegacyHive, another Windows privilege-escalation vulnerability. Earlier disclosures from the researcher included techniques targeting Microsoft Defender and BitLocker-related security mechanisms.

Nightmare Eclipse has said the decision to release zero-days publicly was partly driven by frustration with Microsoft’s handling of vulnerability reports. While many of these disclosures have remained proof-of-concept demonstrations, SecurityWeek notes that some previously released vulnerabilities were later exploited by malicious actors.

That history gives HardBreacher more significance than an isolated vulnerability disclosure.

Public exploit releases compress the defensive window

The episode illustrates the difficult relationship between vulnerability research, coordinated disclosure and public exploit publication. Proof-of-concept code can help defenders understand weaknesses and verify whether mitigations work, but it can also substantially reduce the engineering effort required for attackers to develop functional exploits.

In this case, the immediate risk is moderated by the fact that Kaspersky says a fix is already available. Organizations running Kaspersky Endpoint Security should nevertheless confirm that current updates have been applied rather than assuming automatic updating has completed successfully.

The broader lesson concerns the privileged position occupied by endpoint protection software. These products are designed to become some of the most trusted components on a computer, but that trust also increases the consequences when vulnerabilities appear inside them.

HardBreacher therefore represents an interesting inversion of the normal security model:the software responsible for controlling potentially malicious activity can itself become the mechanism through which an attacker gains greater control of the system.

⁠Original report at SecurityWeek

Key facts

  • Kaspersky's Endpoint Security product was affected by a vulnerability
  • The vulnerability was exploited using a tool called 'HardBreacher'
  • Kaspersky has reportedly patched the vulnerability
  • The exploit was associated with the 'Nightmare Eclipse' activity

Why it matters

The successful exploitation of endpoint security software highlights the persistent threats facing enterprise security products and the ongoing arms race between attackers and defenders. Such vulnerabilities, when weaponized, can undermine trust in security solutions and potentially lead to widespread compromise if not promptly addressed.