THE researcher known as Nightmare Eclipse has released a zero-day exploit called HardBreacher, targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. This exploit allows the attacker to gain control over the Kaspersky UI process, rendering the security software ineffective. Kaspersky has confirmed that the issue has been fixed via automatic updates.
Nightmare Eclipse has also previously disclosed other exploits, including ShieldBreak and LegacyHive, focusing primarily on Windows and Microsoft Defender vulnerabilities.