News Room
16
Share
Critical Entra ID RCE and 'ShieldBreak' Zero-Day Exploited by Lazarus Group
criticalZero-Day Exploits

Critical Entra ID RCE and 'ShieldBreak' Zero-Day Exploited by Lazarus Group

Intelligence confirms active exploitation of a CVSS 10.0 RCE in Microsoft Entra ID and a new Defender bypass dubbed 'ShieldBreak,' enabling SYSTEM-level access on fully patched Windows systems.

27 August 2026Last updated 27 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-69836, CVE-2026-47890, CVE-2026-50656
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

The cybersecurity landscape has seen a significant escalation in the last 48 hours with the confirmed in-the-wild exploitation of two critical Microsoft-related vulnerabilities. The first, CVE-2026-69836, is a maximum-severity (CVSS 10.0) Remote Code Execution (RCE) flaw in Microsoft Entra ID. Simultaneously, a new zero-day exploit dubbed "ShieldBreak" has emerged, targeting Windows Defender to achieve SYSTEM-level privileges by bypassing previous mitigations. These developments, coupled with new disclosures in the Spring Framework (CVE-2026-47890), indicate a high-tempo period of exploitation by sophisticated threat actors.

Threat Analysis

The exploitation of CVE-2026-69836 represents a tier-one threat to cloud identity infrastructure. By achieving RCE within Entra ID, attackers can potentially compromise entire tenant environments, bypassing traditional perimeter defenses. In parallel, the "ShieldBreak" exploit, first identified by researcher "Nightmare Eclipse," demonstrates a sophisticated bypass of the July 2026 patches for CVE-2026-50656. This exploit specifically targets the Windows Defender Cloud Files API, utilizing object manager symlinks and byte-range locks to escalate privileges. Intelligence suggests these vulnerabilities are being actively integrated into the playbooks of North Korean and Russian-aligned APT groups.

Technical Details

CVE-2026-69836 is characterized as a logic flaw in the Entra ID authentication flow that allows for unauthenticated remote code execution under specific configurations. The "ShieldBreak" exploit is more localized but equally dangerous; it abuses the way Windows Defender handles file system objects. Specifically, it leverages a race condition in the Cloud Files API to create symlinks that redirect Defender's high-privilege file operations to sensitive system files. Furthermore, the recent Spring Framework disclosure (CVE-2026-47890) involves stream corruption in Server-Sent Events (SSE), which, while not yet exploited in the wild, provides a new vector for disrupting real-time web communications.

Attribution Assessment

Microsoft MSTIC and Mandiant have linked the exploitation of the afd.sys kernel driver and the subsequent use of ShieldBreak-style techniques to the Lazarus Group (North Korea). This activity is part of a broader campaign, "Operation Dream Job," aimed at deploying kernel-mode rootkits on high-value targets. Additionally, the exploitation of the Entra ID flaw has been observed in opportunistic attacks by Kremlin-linked actors, focusing on data exfiltration from government and defense contractors. The rapid adoption of these zero-days suggests a highly coordinated effort to capitalize on the window between disclosure and patch saturation.

Implications

The convergence of cloud-based RCE and local privilege escalation (LPE) creates a "perfect storm" for enterprise security. An attacker can gain initial access via Entra ID and immediately solidify their presence using ShieldBreak to disable local security controls. This chain allows for deep persistence and lateral movement that is difficult to detect using standard EDR signatures, especially since ShieldBreak specifically targets the integrity of the security provider itself.

Recommendations

Encrygma recommends the following immediate actions: 1. Prioritize the deployment of the August 2026 cumulative updates for all Windows and Windows Server instances. 2. Audit Entra ID sign-in logs for unusual service principal activity or unauthorized configuration changes. 3. Implement strict EDR monitoring for unauthorized symlink creation in the \RPC Control\ directory. 4. Update Spring Framework applications to version 7.0.9 or 6.2.20 to mitigate the SSE stream corruption risks. 5. Enforce phishing-resistant MFA across all administrative accounts to mitigate the impact of identity-based RCE.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo