UPDATE

The zero-day “nightmare” apparently isn’t over for Microsoft, as a disgruntled researcher who’s been feuding with the company for the past three months has dropped yet another proof-of-concept (PoC) exploit for a purported zero-day flaw.

For the second month in a row, that researcher — who goes by the online name “Nightmare-Eclipse” — released a zero-day exploit called RoguePlanet right after Microsoft released its raft of Patch Tuesday updates yesterday, which contained a record 206 CVEs. Some of those updates addressed previous several zero-day exploits published by Nightmare-Eclipse.

The latest zero-day is once again for Windows Defender, the Microsoft security service that was also impacted by other exploits released by Nightmare-Eclipse. The vulnerability this time is exploited by “a race condition, so it’s a hit or miss,” the researcher wrote in GitHub notes for the RoguePlanet release. If successful, the exploit spawns a command shell running under SYSTEM-level privileges, which would give an attacker complete access to a compromised Windows machine.

Related:Security Community Slams US Ban on Exporting Mythos, Fable

Nightmare-Eclipse acknowledged that Microsoft tried to block their efforts to create the PoC and that they worked tirelessly to develop it for most of the month of May, an effort that “drained my soul,” according to the blog post announcing RoguePlanet.

At this time, the PoC does not work in Windows Server because “standard users cannot mount an ISO image.” However, all Windows Server versions are vulnerable if the exploit is redesigned to circumvent the issue, according to Nightmare-Eclipse, who said they won’t redesign it themselves since “I’m done with this bug,” according to the GitHub notes.

The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse. 

Ongoing Dispute With Microsoft

The public dispute between Nightmare-Eclipse and Microsoft has by now been well-documented. It began with the release of the “BlueHammer” exploit in April from the researcher, who at first went by the name “Chaotic Eclipse.” The exploit was for a zero-day tracked as CVE-2026-33825, a time-of-check to time-of-use (TOCTOU) vulnerability in Windows Defender’s signature update workflow. 

At the time, the researcher, who has yet to be identified, threatened Microsoft with more zero-day drops in apparent retaliation for the company’s refusal to properly address its reported vulnerabilities. “I was not bluffing Microsoft and I’m doing it again,” they wrote at the time in a blog post. Nightmare-Eclipse then made good on this threat and disclosed five more PoC exploits for other Microsoft zero-day flaws: RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma. 

Related:HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk

Microsoft released a fix for BlueHammer in its April Patch Tuesday updates. That fix didn’t stop attackers from exploiting BlueHammer, as well as targeting RedSun and UnDefend after Nightmare-Eclipse’s disclosure of those exploits. While Microsoft released fixes for the other exploits, the publication of such PoCs poses considerable risk to Microsoft customers. 

Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, says the situation with Nightmare-Eclipse will probably not end well. “Customers will be affected by these disclosures, even if it means they have to engage their emergency patch process instead of getting exploited,” Childs tells Dark Reading. “I’m not sure what it will take for Microsoft to get this person to disclose their bugs privately, but clearly, they need to work on their outreach skills.”

Microsoft’s Response Drew Backlash

Microsoft was noticeably silent in terms of publicly responding when Nightmare-Eclipse first began releasing exploits, but by the end of May the software giant finally had enough. In a blog post published on May 27, the Microsoft Security Response Center (MSRC) said the six vulnerabilities “were not responsibly disclosed,” and condemned the researcher’s actions, even going so far as to suggest it would pursue criminal charges against researchers like Nightmare-Eclipse that published zero-days.

Related:ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

“Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences,” MSRC said in the post at the time. “Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world.”

Overall, security researchers responded negatively to Microsoft’s statement, arguing that such threats are short-sighted and could potentially lead bug hunters to sell their findings to zero-day brokers and cybercriminals. 

“The feud reads as a breakdown in coordinated vulnerability disclosure, not as random vandalism,” Collin Hogue Spears, senior director of solution management at Black Duck, tells Dark Reading. While Microsoft later walked back its threats, he says a more “durable fix is a disclosure channel that gives researchers a real answer and a fast, explained bounty decision, backed by an explicit legal safe harbor.” 

“It also means ending what researchers describe here: a flaw patched in silence, and then the finder blamed in public,” Spears observes.

Researchers and cybersecurity vendors have previously criticized Microsoft for years over the software giant’s vulnerability disclosure program and its lack of transparency in disclosing certain cloud flaws. In response, Microsoft made vulnerability disclosure and transparency a core pillar of the company’s Secure Future Initiative (SFI) in 2023 and later touted improvements in those areas.

What’s Next for Nightmare-Eclipse?

A Microsoft spokesperson says the company is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. “Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the spokesperson says. 

Microsoft also reinforced its support for coordinated vulnerability disclosure in order to protect customers and support the research community “by ensuring their findings are thoroughly investigated and addressed before being made public,” the spokesperson says.

However, it seems that there likely will be more releases of zero-day exploits for other issues with Windows Defender as well, as Nightmare-Eclipse — despite the admitted degradation of their “mental and physical health” in developing the latest PoC — shows no signs of stopping in their exploit vendetta against the company.

“Microsoft efforts to protect Defender from path redirection attacks are useless,” the researcher wrote in the post. “I have a batch of memory corruption vulnerabilities in defender as well and not to mention the other batch of vulnerabilities I have in several other components.”

This story was updated at 12:30 p.m. ET on June 10 to reflect comments from Microsoft.





Source link

#

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *