Skip to content
The Nexus
DossierENTITY

Nightmare Eclipse

Coverage of Nightmare Eclipse in the Nexus archive.

Earliest in view: May 28 · 20:19 UTCMost recent: Jul 17 · 11:05 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 17 · 11:05 UTCBLEEPING COMPUTER
    New Windows LegacyHive zero-day gives hackers admin privileges

    A security researcher named Nightmare Eclipse has disclosed a Windows zero-day exploit called LegacyHive, enabling attackers to escalate privileges on updated Windows systems. The exploit grants hackers administrative access to these systems.

  • SECURITYJun 10 · 18:45 UTCTHE REGISTER
    Angry bug hunter with Microsoft beef drops new Windows 0-day

    Nightmare Eclipse, a bug hunter with a reported grudge against Microsoft, disclosed a new zero-day vulnerability called RoguePlanet targeting Microsoft Defender on Windows 10 and 11. The flaw allows local privilege escalation to SYSTEM-level access and is part of seven zero-days the researcher has publicly released, accusing Microsoft of ignoring vulnerability reports and refusing communication. Microsoft initially responded with potential legal threats but later clarified it had 'no intention to pursue action' against security researchers.

  • SECURITYJun 9 · 22:07 UTCKREBS ON SECURITY
    A Record-Breaking Patch Tuesday for June 2026

    Microsoft released a record 200 security patches in June 2026's Patch Tuesday, with 30 critical vulnerabilities and public exploits for three flaws. AI tools are increasingly used to discover bugs, and researcher Nightmare Eclipse disclosed multiple zero-day exploits, including CVE-2026-49160 and CVE-2026-50507, sparking controversy over Microsoft's legal stance on researchers.

  • SECURITYJun 5 · 14:48 UTCCYBERSCOOP
    Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away

    Microsoft threatened criminal legal action against security researcher 'Nightmare Eclipse' for publicly disclosing zero-day vulnerabilities without prior coordination. The researcher claimed Microsoft refused to communicate, deleted their security response account, and flagged their GitHub account, escalating a public dispute over vulnerability disclosure practices.

  • SECURITYMay 30 · 15:19 UTCTHE VERGE
    Microsoft is threatening legal action for disclosing exploits

    Microsoft is facing criticism for threatening legal action against an individual who disclosed zero-day exploits. Nightmare Eclipse, a user, posted proof-of-concept exploit code, prompting Microsoft to disable their GitHub, GitLab, and Microsoft Security Response Center accounts. Cybersecurity researcher Kevin Beaumont highlighted Microsoft's response as a point of concern.

  • SECURITYMay 28 · 20:19 UTCTHE REGISTER
    Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops

    Disgruntled bug hunter Nightmare Eclipse (Chaotic Eclipse) has released six Windows zero-days, prompting Microsoft to issue a blog post condemning uncoordinated disclosure and threatening legal action. Nightmare claims Microsoft humiliated them by deleting their MSRC account and withholding payment, vowing a major release on July 14.

Nightmare Eclipse · Dossier · The Nexus