Tech
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
A security researcher has published details of a new vulnerability in the latest versions of Windows that allows hackers to gain system-wide access to the user’s device and data, despite facing a legal threat from Microsoft weeks earlier over the release of previously unknown software flaws.
The new bug, dubbed ShieldBreak, is the latest disclosure by security researcher Nightmare Eclipse, who in recent months has published details of several bugs affecting Microsoft’s products, including Windows.
According to Nightmare Eclipse’s post, ShieldBreak takes advantage of a flaw in Windows Defender, the anti-malware and security engine built into Windows. A successful attack allows the hacker to escalate their permissions from a low-level user to full access to the device and its data.
Nightmare Eclipse published the proof-of-concept exploit as a Windows app, requiring the user to run the app to exploit the bug. The bug works on Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025, the researcher said.
Security researcher Will Dormann verified that the bug works and that Windows Defender must be enabled for the exploit to work.
The latest exploit builds on an earlier exploit that Nightmare Eclipse developed dubbed RoguePlanet. Microsoft rolled out a patch for RoguePlanet, but Nightmare Eclipse implied that Microsoft’s fix was not sufficient and that their latest exploit demonstrates a full bypass of the earlier patch.
Microsoft has not yet released a patch for the ShieldBreak bug. A spokesperson for Microsoft did not immediately comment when contacted by TechCrunch. The bug is considered a zero-day because the software maker — in this case, Microsoft — was given no time to patch the bug before it was publicly disclosed.
The release of this new zero-day is the latest in a long back-and-forth between the security researcher and the software giant over the company’s alleged handling of their bug reports.
In a series of blog posts, the security researcher claimed that Microsoft mistreated them and did not handle their bug reports sufficiently, with the implication that the researcher had no other choice but to publicly disclose the bugs online. Nightmare Eclipse previously released several other bugs in Windows that were later exploited in real-world attacks to hack into organizations.
In May, Microsoft published a blog post threatening to take legal action against security researchers, like Nightmare Eclipse, if they released details of zero-days outside of the company’s disclosure policies. The company faced heavy rebuke from the security community, many of whom described similar experiences with Microsoft’s handling of their bug reports. Microsoft later walked back the comments in a social media post. Its original blog post remains published and unchanged.
ShieldBreak lands a day after Microsoft’s regularly scheduled monthly security patch releases, dubbed Patch Tuesday. This is the second month in a row where the number of patches has reached around 500 or so bugs driven by the company’s growing use of AI to find and weed out security flaws.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Enjoy Hands-On Bitcoin Mining with This $50 Desktop Solo Miner
TL;DR: The BlockChance Bitcoin Ticket Super Miner brings real solo Bitcoin mining to your desktop with Wi-Fi connectivity, 1,060 KH/s of hashing power, and standalone operation for $49.99 (MSRP $99.99).
Bitcoin mining is often associated with large ASIC farms, high electricity costs, and specialized infrastructure. The BlockChance Bitcoin Ticket Super Miner takes a different approach by offering an affordable desktop device that demonstrates how real solo mining works without requiring industrial-scale hardware.
Bring real Bitcoin mining home with BlockChance
The unit delivers approximately 1,060 KH/s (1 MH/s) of hashing power using official NMMiner firmware. After connecting to Wi-Fi and entering a compatible Bitcoin wallet, it begins submitting legitimate solo mining hashes directly to the Bitcoin network. Unlike USB miners or software-based demonstrations, the device operates independently and requires no dedicated computer once configured.
Its compact design features a 1.54-inch display for monitoring hashrate, mining activity, and network status, while Bluetooth Low Energy simplifies setup. The miner is designed to run continuously using minimal power and produces little noise, making it practical for desks, home offices, and lab environments.
It’s important to understand the intended use case. At this hashrate, the probability of discovering a Bitcoin block is extremely low. Rather than functioning as a predictable source of mining income, the BlockChance Super Miner is better viewed as an educational device and a lottery-style participant in the Bitcoin network.
It provides a tangible way to observe mining operations and better understand proof-of-work without purchasing commercial mining equipment.
It’s a cost-effective way to move beyond reading about Bitcoin mining and interact directly with the technology.
Get the BlockChance Bitcoin Ticket Super Miner for just $49.99 (MSRP: $99.99).
StackSocial prices subject to change.
>
Tech
How a $250 million acquisition collapsed into allegations of fraud and forged signatures
When VideoVerse announced its acquisition in September 2025, it felt like a victory for startups across India. VideoVerse was a simple clipping service, but after years of startup incubators and pitching clients, the company had pulled off a $250 million exit.
The acquirer was Minute Media, an international sports publisher split between New York and Tel Aviv, with plans to scale VideoVerse’s clipping software beyond its Indian niche and into the lucrative world of international sports.
Less than a year after the announcement, the deal has unraveled.
Investors are still waiting for their share of the $250 million windfall, and founder Vinayak Shrivastav is now at the center of multiple legal cases. Even the acquirer, Minute Media, seems to be backing away. In May, the company said it was terminating its contract with VideoVerse, underscoring that the two had continued operating as separate legal entities even after the acquisition closed.
Reached by TechCrunch, a Minute Media representative said that “after, among other things, significant discrepancies were discovered in VideoVerse’s representations, Minute Media decided to terminate its engagement with the company.”
If the allegations are true, this was more than just a deal that fell through. Across multiple legal filings, creditors and investors paint a picture of a serially untruthful CEO, who used the guise of a successful business to accumulate cash-generating debts and side deals until the pretense became untenable. The result is an alarming reminder of the limits of due diligence and how much the business of startups still relies on trust.
The sheer volume of legal cases shows that trust is now in short supply. Bluestone Capital, which backed VideoVerse in its 2023 round, is now suing the company for fraud, alleging that the startup violated its investment terms and refused to pay out proceeds from the acquisition. In a separate suit, a creditor is seeking to recover $64 million from a loan that Shrivastav took out shortly after the acquisition closed.
The same complaint alleges that Shrivastav committed fraud during the acquisition itself, claiming he “used fraudulent merger documents that did not reflect the business terms on which Mr. Shrivastav and Minute Media had agreed to induce Clippings’ shareholders to approve the merger.”
Even VideoVerse executives have begun lobbing accusations. The company’s COO alleges in a separate case that Shrivastav forged his signature on loan and share-repurchase agreements, extracting tens of millions of dollars from the company, in the wake of the Minute Media deal.
The Business of Clipping
While not a household name, VideoVerse became a key player in the billion-dollar clipping industry, providing automated tools for editing long-form broadcasts into the shorter clips that travel well on social platforms.
Its flagship product, Magnifi, is an AI-powered tool that can automatically identify key players and moments. Using the software, clients could easily generate packages of every three-point shot in a basketball game, for instance. Backed by an extensive human support team, the platform attracted high-profile clients like the Indian Premier League, FIFA+ and Nippon TV.
It is a lucrative niche, and one in which Minute Media had hoped to expand to the U.S. market before VideoVerse’s internal problems surfaced.
Even across the multiple cases against Shrivastav, there are conflicting claims and inconsistencies, as investors struggle to make sense of the current state of the company. What is clear is that tens of millions of dollars are missing, and there are already disputes about where the money went and how much is owed to whom.
In October, Shrivastav approached the investment firm Lingotto, arranging a $55 million structured loan — supposedly to satisfy an earlier creditor. With the Minute Media merger already public at more than four times that amount, it appeared to be a safe bet. The financing was even backed by statements from the creditor and Minute Media’s own CEO. According to a court filing from Lingotto, $53 million was transferred to an account controlled by Clippings on October 1, backed by a standard repayment schedule.
But Lingotto now says critical documents provided by Shrivastav were forged. Minute Media’s CEO never signed the documents, the lawsuit alleges, and screenshots purporting to show internal bank balances were also fabricated.
According to the terms of the loan, Lingotto was owed a $4 million payment on March 31, but it never arrived. When the investment firm called in the full amount of the loan with interest, it discovered a long list of people waiting to be paid by VideoVerse. A separate loan from Bluestone Capital had gone into settlement a few months prior, with similarly overdue payments. By the end of April, Shrivastav was out as CEO.
The following months have produced a web of overlapping court claims, as Minute Media, Lingotto, and Bluestone each seek restitution in Delaware Chancery Court. A separate claim from former COO Sabya Das alleges a more complex tangle of fraud involving secondary sales and a confidential high-interest loan.
Shrivastav did not respond to multiple attempts to contact him for this story. His most recent listed address, which appears in Das’s complaint, is on the Palm Jumeirah islands in Dubai.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
UC San Diego CHARM Smart Ring Tracks Glucose Through Sweat
Glucose tracking may eventually be as simple as wearing a ring.
UC San Diego researchers have developed CHARM, a smart ring prototype that reads glucose from sweat collected at the finger. Early human testing compared its estimates with commercial CGMs and blood-glucose meters to see whether a finger-worn device could follow glucose changes throughout the day.
A ring could make glucose monitoring feel less intrusive and easier to fit into daily life if the technology proves reliable.
CHARM collects sweat without a workout
CHARM does not need you to work up a sweat. According to UC San Diego, a soft hydrogel inside the ring passively draws tiny amounts of fluid from the skin. A small channel carries the sweat across sensors that detect glucose.
Glucose in sweat is not the same as a blood-glucose reading. Researchers use personalized calibration to estimate corresponding blood-glucose levels, then CHARM sends the data wirelessly to a phone. People familiar with wearables for blood sugar tracking will recognize the app-connected setup.
Battery life reaches about 12 hours in the current prototype. Sensing hardware and wireless electronics fit inside the ring itself.
Early tests tracked commercial monitors closely
Researchers tested CHARM with healthy participants and people with type 1 diabetes, comparing its estimates with commercial CGMs and blood-glucose meters. Results published in Nature Communications showed that the ring captured the same meal-related rises and falls seen in the reference readings.
Some sweat-based readings lagged blood measurements by roughly 15 to 20 minutes in individual tests. Researchers also reported that personalized calibration settings remained relatively stable for about two months.
More health data fits into the same ring
CHARM can monitor ketones alongside glucose, with researchers also checking those readings against commercial blood measurements.
Sensors can be configured for lactate and uric acid. Vitamin C and alcohol are supported too, with up to four biomarkers monitored at once.
Consumer products currently take a different route. Oura Ring, for example, gets glucose data from Dexcom Stelo. Smartwatches used for glucose tracking generally display readings supplied by a compatible CGM. CHARM puts the sensing technology on the finger.
Everyday glucose tracking still has hurdles
A ring-based glucose sensor could appeal to someone tired of juggling multiple devices. People already getting blood sugar alerts on their smartwatch could benefit most if a ring reduces the gear and upkeep involved in daily monitoring.
If you are watching this category, focus on the basics before getting excited. Accuracy during fast glucose changes and calibration frequency come first. All-day battery life and water resistance will help determine whether a ring can stay on through normal routines.
Researchers still have work to do in those areas. Broader clinical testing and better water resistance remain priorities, and the prototype’s current battery life falls short of the multi-day wear people have come to expect from smart rings.
CHARM remains a research prototype and is not commercially available. FDA guidance says no smartwatch or smart ring has been authorized, cleared or approved to independently measure or estimate blood glucose without piercing the skin. Anyone relying on glucose readings for treatment decisions should continue using an FDA-authorized glucose monitor.
Read our breakdown of five smartwatch health alerts worth knowing across Apple, Samsung, Google, Garmin, and Huawei devices.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
