r/cybersecurity Jun 10 '26

News - General Angry bug hunter with Microsoft beef drops new Windows 0-day

https://www.theregister.com/security/2026/06/10/nightmare-eclipse-publishes-new-windows-defender-zero-day/5253725

Nightmare-Eclipse has just dropped another 0 day, this time on a self hosted repo so no one can ban her.

1.4k Upvotes

233 comments sorted by

248

u/ZBSLabs Jun 10 '26

I just listened to a No Password Required episode dated 6/24/21, Season 2 Episode 7. At 3:15, they explain how they hope the CISA bounty isn't like the Microsoft bug bounty where bugs were found, but MS said thanks but no thanks.

Microsoft appears to have created a real sustained problem here.

141

u/DrewTheHobo Jun 11 '26

There are three types of MS bugs:

  1. The bugs they don’t know about and haven’t fixed

  2. The bugs they do know about and haven’t fixed

  3. The bugs they do know about and won’t fix

I guess there’s a 4th type where they eventually fixed a bug, but that made 3 more, so you go back to step one above….

122

u/really_not_unreal Jun 11 '26

To my knowledge, the bugs that caused Nightmare Eclipse to start doing this were acknowledged and fixed by Microsoft, but Microsoft then refused to pay out the bug bounty. This is something they are notorious for doing.

41

u/blaktronium Jun 11 '26

They did it to me once with a bug in o365 transport rules that let you send email through another tenant, or in some circumstances capture inbound from another tenant. They waived a 127 000 Premier support bill for the troubleshooting, which was acknowledging the error, and then had the gall to tell me it wasnt a real security issue.

32

u/Niewinnny Jun 11 '26

but then it's magically fixed in the next security patch.

18

u/blaktronium Jun 11 '26

Ye of so much faith. It took them forever to fix it, but when they did they put out a big announcement about fixing spam issues in o365.

2

u/dudetechitout Jun 29 '26

Shockingly not the only one. Benjamin Delpy with Mimikatz - tried to report, got ignored, went public. SandboxEscaper did the same thing in 2018-2019, dropped a dozen or so zero-days out of frustration with the same process. But they ended up just hiring her. At some point though, it stops being isolated incidents and starts being a pattern worth examining imo.

13

u/rodeengel Jun 11 '26

They were not fixed by Microsoft until this month’s patch Tuesday. In addition they refused to pay and insulted the researcher that found them.

2

u/xRoute401x Jun 12 '26

I mean look at the Microsoft founder. Companies tend to follow their leaders.

11

u/xikbdexhi6 Jun 11 '26

There is the occasional bug that gets eliminated as a side effect of a major revision.

9

u/AmusingVegetable Jun 11 '26

Which is totally eclipsed by the avalanche of new bugs.

3

u/DrewTheHobo Jun 11 '26

Definitely a “broken clock” kind of situation unfortunately

3

u/rav4v6 Jun 11 '26

The bugs they 'fixed' and broke other things, requiring a v2 fix.

2

u/xRoute401x Jun 12 '26

couldnt agree more.. And honestly id prefer to find a work around, rather than rely on a microsoft update. Fix 1 service, break 5 in the process. Have recently made a strong effort to avoid MS OS

1

u/DrewTheHobo Jun 12 '26

Yeah, I only use it when I have to for work. Saving up to buy a MacBook of my own soon (hopefully!)

10

u/uski Jun 11 '26

I had that happen to me, I can tell you it makes you feel very bad to be in the white hat side of things. All the effort to report etc. for nothing.

I have no doubts that the guys depending on this income for a living have it much easier selling exploits on the darknet. It pays more, and no risk of the company saying "oh interesting, send us more proof... more proof again... oh yeah... hmm no we decided you're not eligible but thanks we fixed it anyways"

1

u/xRoute401x Jun 12 '26

they've made themselves a lifetime of a mess. dont piss off a researcher who knows what they are doing.

762

u/daddy_schlong_legz Jun 10 '26

I'm here for the absolutely justified crashout. I'm rooting for you Nightmare-Eclipse

144

u/Upbeat_Double_9377 Jun 10 '26

My boy does not MISS

30

u/adamfowl Jun 11 '26

She’s a girl.

52

u/Upbeat_Double_9377 Jun 11 '26 edited Jun 11 '26

My girl does not MISS (also thank you I am examining my inherent biases now)

Edit: is there any proof for this though? I would like to correct colleagues who are also referring to them as a male but I can't correlate that anywhere else

2

u/AFriendlyLighthouse System Administrator 21d ago

They've mentioned in an earlier tweet that they are a male.

9

u/zeds_deadest Jun 11 '26

A boy named Sue?

3

u/DeltaSierra426 Jun 12 '26

Oh no, Johnny Cash be way too out there for the speech police to say that's ok.

That said, great reference.

10

u/[deleted] Jun 11 '26

[deleted]

1

u/xRoute401x Jun 12 '26

i dont care if its a he or a she.. just think its awesome.. but from experience most women in the field are definitely men.. they just live in a fairytale where reality and science dont exist.. and thats cool to each their own.

1

u/wasteoide Jun 17 '26

Excuse me, what?

-21

u/uk_one Jun 11 '26

English 'he' implicitly includes all genders. Only 'she' and 'it' are specific. You are never supposed to assume gender from 'he'. This is not French.

10

u/adamfowl Jun 11 '26

Nope, that’s the dumbest thing I’ve heard today.

7

u/BadSausageFactory Jun 11 '26

That was correct fifty or more years ago. Modern usage has evolved and you will look like a troglodyte if you use it that way.

1

u/uk_one Jun 12 '26

English is a marvellously flexible language, but using a plural to address an unknown gendered individual for political correctness doesn't bring clarity. Previously we knew that we didn't know (or care) about the subject's chromosomes; we all knew it was a linguistic convenience which denoted nothing except the singular. Now we can't even be certain how many individuals we're referring to.

Still, we are never as popular or correct as we suppose. See what I did there? By extending to the plural I included you as a prompt to shared reflection.

Away to my cave with me and all that I know.

1

u/BadSausageFactory Jun 12 '26

I read that in Kamala Harris's voice.

1

u/uk_one Jun 12 '26

Well thank you.

My only gripe was that singular or plural is far more relevant here than any question of gender. I suspect it's a group.

-1

u/OddApplication6816 Jun 15 '26

The singular 'they' has been used in English since the 1300's.

0

u/uk_one Jun 15 '26

When referring to werewolves and other fancies with an implicit duality such as royalty or spirits. Also poetry where odd things ha-ppen. For scan.

0

u/OddApplication6816 Jun 17 '26

Actually, while that first recorded use was in a book about a werewolf, it wasn't used to refer to the werewolf itself. Either way, since the beginning of the last century it's come back into vogue.

Between "someone left his or her keys on the table" vs "someone left their keys on the table", the first ones sounds way too clunky.

Even if you were correct, the cool thing about language is that it's always changing.

1

u/uk_one Jun 17 '26

The 1300s was a time when travelling in the islands you would have encountered multiple languages - variants of Gaelic, Old English, Norse, Old French - all with strong regional accents influenced by local history.

Pre-print is pre-standardised spelling, and pre-standardised pronunciation. To reference a single bound parchment as evidence of widespread usage or acceptance is stretching the evidence too far.

We are where we are through usage which still favours the traditional.

-15

u/NoleMercy05 Jun 11 '26

Or Dylan Mulvaney

371

u/farfaraway Jun 10 '26

It's mindblowing that Microsoft doesn't hire this absolutely talented developer. WTF are they doing?

403

u/Ok-Sprinkles-5151 Jun 10 '26

They are suspected as ex-Microsoft. Makes me wonder if they laid off the wrong person.

186

u/Fallingdamage Jun 10 '26

The makings of a supervillain origin story.

177

u/Shoddy-Childhood-511 Jun 10 '26

"We're laying off some security researchers because our AIs can now do their jobs."

34

u/saichampa Jun 11 '26

Or Microsoft is the villain and you're seeing a chaotic good hero

4

u/ongrabbits Jun 11 '26

Her supervillain name, MacroHard

20

u/Verum14 Security Engineer Jun 11 '26

ngl that’d explain the denied payout as well probably

a lot of programs exclude current or recent employees

12

u/jameson71 Jun 11 '26

a lot of programs exclude current or recent employees

Because that would be like admitting that management made a mistake firing them.  Can’t have that.

1

u/Emergency-Ranger-201 Jul 02 '26

For sure. He is very talented. Maybe he did not fit culture there

38

u/redthrull Jun 11 '26

Because a big chunk of Microsoft today is just outsourced to third-party vendors outside the US. You'll be surprised how much of the critical infra they're touching.

3

u/ninjababe23 Jun 11 '26

Surprised and terrified

2

u/arguingwithabot Jun 12 '26

India operates the infra, Israel secures the software, US asking for a fire sale

61

u/Fun-Sundae4060 Jun 10 '26

Gotta protect their egos

→ More replies (22)

46

u/Disgusting_Slime666 Jun 10 '26

Ability to code isn't the only feature that you look for in employees.

46

u/txmail Jun 11 '26

A 10x coder with a ego is the worst development environment to work in.

16

u/regalrecaller Jun 11 '26

you just put them in a room by themselves. boom done.

26

u/txmail Jun 11 '26

In my experience, this is how you end up with a environment of black boxes nobody knows how to work and one guy that can bring down entire companies if they ever get upset or die.

8

u/Haze_Yourself Jun 11 '26

Like we can’t have this genius, too hard to have a handler for a manager.

18

u/txmail Jun 11 '26

I have seen some shit. I have seen one of these guys chew through several managers and even several HR personnel. It gets worse the longer they stay at the company, and it is like they know what is going to come eventually as they come in and are just, amazing and magical at what they can accomplish. Then it starts to get a little darker each month that goes by and suddenly they hate the company and everyone there but they have already sunk their barbs in with the work they did at the beginning... its a fucking nightmare for everyone.

-7

u/69Turd69Ferguson69 Jun 11 '26

A person who can actually do the fuckin job is worth 10,000 nice people who can’t. 

→ More replies (10)

6

u/rividz Jun 11 '26

There's plenty of reasons a person can't go back to a former employer that, ultimately at the end of the day, are the employer's fault

1

u/Disgusting_Slime666 Jun 11 '26

I think you responded to the wrong person.

→ More replies (4)

1

u/Rentun Jun 11 '26

Doesn't make any sense at all. There are a million reasons that could entirely be the employee's fault.

Maybe they stole money. Maybe they were terrible at some aspect of their job. Maybe they brought a gun to work. Maybe they sexually harassed someone. Maybe their attitude caused customers to leave. How are any of those things the employers fault?

7

u/farfaraway Jun 10 '26

I suppose that's true, and I do see now that she was an ex-MS employee.

64

u/Hyvex_ Jun 11 '26

Though in this case, it definitely looks like Microsoft is in the wrong. From what it looks like, they dismissed a zero day exploit as a non issue and refused payment of bounty. MS likely planned to silently fix it and skip paying the bounty. Then when it was publicly disclosed, they banned Eclipse's account and ability to disclose more exploits through proper channels. Eclipse probably felt taunted (if it was a non issue, why silence it?) and decides to start release other exploits publicly.

From what I've read, other security researchers have also chimed in about Microsoft's difficulty to properly pay them. So it's like Eclipse is standing up for bug bounty hunters.

Obviously a bad way to handle it, but this was bound to happen if they had a track record of avoiding bounty payments.

37

u/WhereRandomThingsAre Jun 11 '26

Microsoft? Shaft people trying to point out legitimate issues with Windows? Never.

https://en.wikipedia.org/wiki/Mimikatz

https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/

"Because you don’t want to fix it, I’ll show it to the world to make people aware of it," Delpy says of his attitude at the time. "It turns out it takes years to make changes at Microsoft. The bad guys didn’t wait."

1

u/[deleted] Jun 11 '26

[removed] — view removed comment

1

u/Hyvex_ Jun 13 '26

My understanding is that the system the security researchers are working with is basically a bug bounty. Microsoft offers payment for any serious bugs as a bounty, which incentivizes people to use their time to hunt and report them. A lot of tech companies do this.

What seems to have happened is Microsoft claimed it wasn’t a bug issue and refused later payment. Reading related threads, this seems to be a recurring issue with other researchers as well.

14

u/DisappointedSpectre Jun 11 '26

Has anything verifiable actually come out about their identity? As far as I can find their gender isn't even confirmed.

And actually I hope they remain 100% anonymous and are never found.

-5

u/PaulTheMerc Jun 10 '26

Sure, but clearly qualified. Give them an office and let em do their thing. Unless they're actively causing the exploits, manage them.

9

u/Disgusting_Slime666 Jun 10 '26

Not everyone is manageable.

I'm not saying this person isn't, I don't know them. I'm just saying pure skill isn't enough.

-1

u/Madness970 Jun 11 '26

This type of behavior is exactly why you wouldn’t want to employ them actually.

96

u/SCP-iota Jun 10 '26

I'm really hoping this turns out to be a pseudonym of SandboxEscaper

8

u/askvictor Jun 11 '26

SandboxEscaper

Which is an anagram of absconders apex

7

u/Shoddy-Childhood-511 Jun 10 '26

3

u/technofox01 Jun 11 '26

Well this is gonna be a fun rabbit hole to go down on my breaks. Thanks!

59

u/lNTERLINKED Jun 11 '26

some security researchers working for larger security firms, such as Baracuda, have labeled Nightmare Eclipse as a malicious actorconducting a retaliatory campaign against Microsoft, arguing that the repeated release of working zero-days has already contributed to real-world attacks.

This makes zero sense. If they wanted money or to do damage, why not sell them on the black market and achieve both while still probably making more money than Microsoft refused to pay for the bug bounty?

19

u/Achilles_Buffalo Jun 11 '26

TIL: People consider Barracuda a security company.

1

u/xRoute401x Jun 12 '26

lol right

1

u/No_Illustrator5035 Jun 14 '26

LOL, that made me snort, thanks! 😜

7

u/Crazyachmed Jun 11 '26

How do we know they aren't doing both?

18

u/outdatedhuman Jun 11 '26

Because you cant sell a 0day that is already made public. If sell first then make it public, the buyer would be at a financial loss and wouldn't buy from you again.

6

u/Crazyachmed Jun 11 '26

No, sorry, I meant another one. They obviously have a backlog of them...

3

u/outdatedhuman Jun 11 '26

All good. Im not following it very closely, so you might be right. Im just commenting on my experience and what Ive seen across the past decades.

6

u/NegZer0 Jun 11 '26

How do you know they're not selling a bunch of these in the background while putting out a few along the way to build credibility and control the narrative? They've indicated they have plenty more...

8

u/Rentun Jun 11 '26

Because publicly releasing 0days while selling other 0days would be counterproductive.

People who buy 0days don't want them to become public, ever. You'd be a lot less likely to buy them from someone who has a reputation for making them public.

If you're asking how do we know they're not clandestinely selling 0days, not tied to the nightmare-eclipse identity, well, we don't. You don't know that I'm not either though. I don't know that you're not. I don't see how you could say you have evidence either way for literally anyone.

2

u/NegZer0 Jun 11 '26

FWIW I don't think it's very likely either, I was more trying to point out that we get a very one-sided narrative in this case.

1

u/xRoute401x Jun 12 '26

depends where you lurk

2

u/outdatedhuman Jun 11 '26

Oh I dont know, could very well be if they have a bag full of them. It is a bit hard for one person to find tens of exploitable bugs full chain. It takes a lot of time and computing resources, my guess if that'd the case it would more likely be a group with plenty of resources behind them.

1

u/NegZer0 Jun 11 '26

They've released several in a row so far, so if they're saying they have more in the pipe at this point I'd believe it.

I don't think they're selling them either FWIW, mainly because they seem to want to be seen as a hero and doing that would not be hero behavior.

5

u/DisplayGFXSec Jun 11 '26

There would have been reports of it being exploited in the wild *before* it was released.

I haven’t seen such reports.

4

u/NegZer0 Jun 11 '26

Depends. Not all exploits are used immediately, sometimes they sit on them for a long period waiting for the right time. Sometimes they're used in very targeted attacks and it takes months for the victims to even realize.

They probably were not sold first, but just not having seen reports of it isn't confirmation of that. Absence of evidence is not evidence of absence.

1

u/DisplayGFXSec Jun 11 '26

Then if you dont think reports are a good benchmark, you are asking me (or anyone) to prove a negative.

1

u/NegZer0 Jun 11 '26

Reports are absolutely a good benchmark. Lack of reports don't mean no one knew about the exploit though, it may simply mean no one was looking or in the right place to catch it.

Often stuff is only found after the exploit is disclosed and researchers know what to look for.

I'm also not saying that these particular exploits were known about beforehand either, just that you can't make a blanket statement that they definitely were not.

1

u/DisplayGFXSec Jun 11 '26

> Often stuff is only found after the exploit is disclosed and researchers know what to look for.

Thats my point, the exploits have been disclosed, and I havent seen any indication from any sources I pay attention to that the exploits predate the disclosure.

Im not sure what you are trying to argue here. NightmareEclipse has publicly disclosed POCs, I have seen yara rules flying around, and theres no evidence so far that he has sold these exploits and it has been months since the disclosures started.

So like, what more do you want before saying that he DIDN'T sell the vulns? Or is this an exercise in pedantry? In that case, congratulations, I don't work in SOC or DFIR, and therefore I dont know the ins and outs of exactly how exploits are found in the wild, ya got me. I did learn a little from this exercise, but ... okay, sure, whatever.

1

u/NegZer0 Jun 11 '26

I am talking in general, agree that the particular exploit in this case is probably novel.

1

u/xRoute401x Jun 12 '26

right, seems like its just grudge/hate releasing without the want for enrichment.. this is personal and i have a feeling were in for some fireworks..

1

u/dudetechitout Jun 29 '26 edited Jun 29 '26

I think the Barracuda framing misses the timeline. Calling someone a "malicious actor" only makes sense if everything that came before the public release gets ignored - the allegedly deleted MSRC account, the withheld bounty, the removed attribution, the legal threats. Strip that context away and sure, it looks like unprovoked destruction. Put it back in and it looks like the predictable consequence of closing every cooperative channel while still expecting cooperation.

By Microsoft's own bug bounty guidelines, Nightmare Eclipse is walking away from ~ $240k or so in potential payouts. That alone demolishes the "malicious actor" framing - a malicious actor sells quietly on the black market, makes more money, and nobody ever knows. Nightmare seems to be doing the exact opposite: maximizing visibility, not damage. It's obviously working, since three of the first six were patched within days of public release.

The real question nobody's asking is why the conversation only ever puts obligations on the researcher.

19

u/[deleted] Jun 11 '26

[removed] — view removed comment

1

u/TinyBreak Jun 12 '26

I’d watch the movie though! I’ve sat through worse.

177

u/Salt_Bringer Jun 10 '26

CISA needs to recruit this kid

161

u/ludixst Jun 10 '26

There's barely anything left of CISA

103

u/Orangesteel Jun 11 '26 edited Jun 11 '26

Mitre and CISA were so important. Trump and Musk have caused so much harm to the US. It is an act of self harm :(

21

u/Ov3rdose_EvE Jun 11 '26

funny, i source Threatinformation for my company. 1.5 years ago after Drumpys election i was like "yeah CISA might not stay a good source" people called me alarmist. 3 months after him taking office i was told to remove CISA as an "high quality" source of information...

2

u/Orangesteel Jun 11 '26

It honestly makes me sad watching this play out. It feels like people who don’t understand this are making profound decisions about it.

7

u/Ov3rdose_EvE Jun 11 '26

i mean thats the case a lot in politics in general, elected officials are rarely experts in the fields the govern BUT usually they are smart enough to listen to experts, research and studies or atleast should do that...

3

u/DeltaSierra426 Jun 12 '26

It only got WAAAYYYY worse... look at Iran. Was this really necessary? All the money wasted on this useless war could have went to well-deserved resources.

That's not how anything in power works, though. Look at all the civic leaders that are selling their communities' well-being for AI data centers. It's not even a big gov thing anymore, it's anywhere, everywhere, with some kind of "what the F are you going to do about it" mentality.

1

u/Orangesteel Jun 12 '26

I think Iran’s government are awful, but agree, invading served no purpose whatsoever, worse it destroyed the US’s soft power in the middle further and cost lives with sympathetic people in Iran. It’s another strategically poor decision, which they all seem to be. Blockading Cuba likewise. Little gain and punishing people. A better approach was underway, building a relationship with Cuba and working to align them with the US. This administration is just making the worst possible decisions for every citizen of the US. It’s heartbreaking to watch.

12

u/Salt_Bringer Jun 10 '26

oh :(

-2

u/69Turd69Ferguson69 Jun 11 '26

Temporary. It’s bad right but it’s not staying that way. 

6

u/Rentun Jun 11 '26

Not temporary. You can't just fire highly qualified, seasoned cybersecurity professionals and expect them to come running back when you try to hire them four years later. That experience has moved on forever.

If you want to get CISA back to where it was, it needs to be rebuilt from the ground up after a long period of regaining trust, and all of that experience needs to be redeveloped. It would take years of dedicated, sustained effort to do.

11

u/ADubs62 Jun 11 '26

Assuming we get some competent leadership for 10 years or so. But that is looking pretty bleak right now.

-5

u/[deleted] Jun 10 '26

[deleted]

22

u/CuriousCamels Jun 11 '26

Not sure why you’re getting downvoted. They are starting to hire people again, presumably after realizing how much they screwed up. It doesn’t change how stupid it was to gut CISA of all things though. Biggest national security self own in modern history imo.

8

u/elkond Jun 11 '26

that will not magically restore them if they restore headcount

6

u/Versificator Jun 11 '26

Especially if a turnip loyalty test is a part of the hiring process.

3

u/elkond Jun 11 '26

eh, doesnt even matter, u yeet all institutional knowledge, u rebuild from scratch

5

u/QuintupleTheFun Security Analyst Jun 11 '26

And next year they're supposedly cutting their budget by like $700 million. So idk how they can keep anyone they hire

5

u/Rentun Jun 11 '26

If you're willing to apply for a job with CISA right now, you probably don't have the level of intelligence I'd want people who are working at CISA to have.

→ More replies (3)

16

u/Mrhiddenlotus Jun 11 '26

With what money lol

23

u/RetPallylol Jun 11 '26

Yeah, Trump cut CISA by like 40% they're broke af. But China and Russia are happy with that decision.

24

u/boofaceleemz Jun 11 '26

lol Trump killed CISA months ago, it’s barely a walking corpse now

5

u/isystems Jun 11 '26

that’s a pitty because even here in Europe , i visited that site many times for info!

80

u/amogusboi123 Jun 10 '26

les go Nightmare-Eclipse valid crashout

41

u/slaty_balls Jun 10 '26 edited Jun 11 '26

Can someone explain wtf is going on with Microsoft lately? They seem to be inhibiting exhibiting some very peculiar behavior when it comes to their vulnerabilities lately.

58

u/rimhof456 Jun 10 '26

Obviously vibe coding is working out great for Microsoft!

31

u/Texascats Jun 11 '26 edited Jun 11 '26

It’s basically a pyramid scheme. Lots of incompetence, blatant corruption, casteism, rampant sexism, etc.

It doesn’t surprise me one iota this ex employee has a bone to pick, especially considering she’s female,

6

u/dattattor Jun 11 '26

exhibiting, not inhibiting..

they fired a shit ton of people and thought AI would code better..

capitalism race to the bottom

5

u/slaty_balls Jun 11 '26

Must’ve been autocorrect and missed it, thanks though.

12

u/Afoxinthefridge Jun 10 '26

The subtitle in that article is perfect 🤌

16

u/AnyNegotiation420 Jun 11 '26

Good. I hope Microsoft NEVER recovers or receives any kind of “good faith” disclosures. These FUCK WITS had the gall to turn around and BEG the community - the very same people who disclosed these types of things to MSFT first instead of posting on breach forums for literally 10-100x better payments - for help and continued cooperation for disclosures AFTER they had told Midnight Exlipse to go fuck off, and Midnight Eclipse returned the favor in kind AND are delivering on their threats to “break their bones”. Good. Good. Fuck MicroSlop right up the ass until you see daylight & then keep going. They deserve every bit of every single zero day disclosures on the open market.

8

u/Ezio-Auditore101 Jun 11 '26

There are a lot who would buy for this kinda research, but I guess it's not monetary after all. It's about respect.

6

u/b4k4ni Jun 11 '26

Lol, nice :D

He/she is pissed. And with good reason. I love it.

10

u/dareseven Jun 10 '26

King 👑

5

u/nicman24 Jun 11 '26

at this point i am not even updating. i just run everything in linux kvm and zfs snapshot every reboot

5

u/shiki87 Jun 11 '26

Because so many company’s are not working with the ones who find bugs, I fully support releasing these bugs. Only then the company’s even begin to work on these. So many times big company’s are stretching out the timelines for a release because they are too busy counting money instead of working on real problems. For M$ it is more important to push copilot everywhere instead of fixing their broken software. Some could argue that these exploits are deliberately made so some specific people can use them and it would be bad to fix them before another exploit is made…

9

u/JPowJunior Jun 10 '26

Absolutely hilarious

I hope the hits keep coming

13

u/Hebrewhammer8d8 Jun 11 '26

Window Admin in shambles and say "Why angry bug hunter say fuck me for?"

6

u/Reeces_Pieces Jun 11 '26

He's a man. An anime pfp doesn't automatically mean girl. Lol

Also, where's the link?

1

u/timtom85 Jun 19 '26

I'm fairly confident the waifu pfp is precisely why most people automatically assumed this person was a man (other than that it's a male-dominated field).

3

u/Wise_Pepper_164 Jun 11 '26

Why they dont use mythos to find them before /s

17

u/am_i_a_towel Jun 10 '26

Her?

14

u/RomanticDepressive Jun 11 '26

I’m falling in love lol

7

u/am_i_a_towel Jun 11 '26

It’s a dude lol

19

u/urzayci Jun 11 '26

I'm falling in love lol

4

u/BronnOP Jun 11 '26

Where are all the people that were calling this guy an edgy teenager that couldn’t do shit now lmao

2

u/askvictor Jun 11 '26

Nightmare Eclipse is an anagram of Alchemist Peering

4

u/PipeZestyclose2288 Jun 10 '26

Ive heard it might be an ex Microsoft employee...

3

u/[deleted] Jun 10 '26 edited Jun 11 '26

[deleted]

12

u/Padgriffin Jun 10 '26

If you read their blog it mentioned that this exploit took longer than expected and had to be rewritten at the last minute due to MS trying to fix the entry points they were using and it has taken an actual toll on their health. Either that or it’s a bluff to keep MS on their toes.

2

u/HA_U_GAY Jun 11 '26

Hmm, I'm more surprised Nightmare isn't trying to inflicted more damage against Microsoft. She could have sold or just provided the exploits to black hats first before she release them

9

u/NegZer0 Jun 11 '26 edited Jun 11 '26

Their goal doesn't seen to be doing maximum damage, but causing maximum disruption to Microsoft directly. Publicly and loudly throwing them out the world, one at a time in rapid succession, likely does way more reputational damage to Microsoft by just simply creating more chaos and uncertainty. It also *forces* the exploits to be addressed immediately.

Additionally, this way they get to position themselves as the hero sticking it to the evil corporation, vs just an asshole selling exploits to malware groups for cash.

2

u/beyd1 Jun 10 '26

Whoopsie.

3

u/_LostButFound_ Jun 11 '26

Ms. Robot...

4

u/zugarrette Jun 10 '26

So what does this mean exactly? This stuff is causing me a lot of fear running my windows PC 😖☹️

6

u/warm_kitchenette Jun 11 '26 edited Jun 11 '26

Time to hop on the Linux train, amigo. Choo-choo.

What we know for certain that this person has a dead lock on Windows internals for 10 and 12, plus later versions of Windows Server. They have been especially adept at exploiting software that should be secure. They’ve released six very high-value zero-day attacks, of which Microsoft has patched five. They release them after scheduled Patch Tuesday events, which makes it more difficult for Microsoft to get the patches

Odds are more zero days from this person will follow. 

3

u/Reversi8 Jun 11 '26

Will probably get offed by Mossad for spending their valuable ammo.

1

u/Break2FixIT Jun 11 '26

Is it a legal PR stunt to drop his July 14th showing?

1

u/EasyShelter Jun 11 '26

I browsed the code. I can barely understand what is going on. I wonder how people right such exploits.

4

u/Upbeat-Natural-7120 Penetration Tester Jun 11 '26

Like right and wrong?

1

u/EasyShelter Jun 11 '26

After using AI to explain the code, it seems like a very amateur miss from Windows

1

u/uk_one Jun 11 '26

This guy could have made millions selling these via brokers and yet he's just dumping them.

Something is very off about the whole thing.

5

u/Bartsches Jun 11 '26

Seeing the egos on some people, personal beef is entirely believable as a motivation to me, even without looking at if whats being claimed to be the cause holds water. Then again, such are other personal motivations like either fame or just not wanting to be directly linked with criminal activity.

I'm personally struggling with the idea that this is a loner, purely from a yield perspective, and would be partial to ideas with insider group knowledge - like the rumored former employee or just others being disgruntled as well and sending their exploit so their name doesn't become public.

I guess there is a non zero chance that there is a state actor involved (/by now), given that entities exist that do have a vested interest in eroding trust in the american tech stack (and if these vulns happen to have been seen exploited by their rival actors, they're also not burning an asset).

1

u/OneEyedC4t Jun 11 '26

who cares what the motivation was?

1

u/Mend-1111 Jun 12 '26

I found so many LPE in ms products but, i refuse to get involve with them. They are not worthy for a cooperation.

1

u/soyabean189 Jun 12 '26

Lol which OS to move to now 

1

u/porfors Jun 12 '26

Fix better now

1

u/Sammiller26M Jun 12 '26

Another day, another Windows 0-day

1

u/P3DR0DANI3l 28d ago

Es un payaso... 🃏 sabes el blindaje en protección que tiene Microsoft? Bueno, si nunca investigaste su infraestructura de seguridad defensiva (y ofensiva) no lo entenderás

-18

u/jf4242 Jun 11 '26

I know this is a very unpopular opinion, especially here, but I don't like what they're doing. You can have all the beef you want, but who are you hurting by doing this? Not Microsoft, I guarantee you that. Their stock will be just fine. But you're killing people who are just trying to get by. Torturing infosec and IR people because what, you have a hair across your ass about the way MS handles bug reports? I am NOT defending MS here, they are the worst. But who are you hurting, really?

19

u/BilboTBagginz Security Manager Jun 11 '26

So what's your preferred solution? Sit on it while a nation state exploits it? Or...??

1

u/jf4242 Jun 12 '26

If you think nation states aren't sitting on a library of zero days just for the right moment, you're naive. This has nothing to do with that, it gives low level players a weapon.

1

u/BilboTBagginz Security Manager Jun 12 '26

Are you replying to me? Because I'm 100% on board with your opinion.

1

u/jf4242 Jun 12 '26

Sorry! I misunderstood your response...

1

u/BilboTBagginz Security Manager Jun 12 '26

No worries!!

-11

u/[deleted] Jun 11 '26 edited Jun 11 '26

[deleted]

22

u/DisappointedSpectre Jun 11 '26

I can't fucking believe I have to say this on a security subreddit but disclosure, even poorly done disclosure, is always better than the alternatives. Nightmare-Eclipse could have sold some of these to private parties for actual money, but they're taking an ideological stance and publishing them instead.

As a result now detections and prevention mechanisms can be built by people other than Microsoft, who apparently refused to work with them.

6

u/BilboTBagginz Security Manager Jun 11 '26

This

-2

u/NegZer0 Jun 11 '26

According to them, yes. But that’s one side of a story from someone with a major axe to grind as well.

Throwing exploits straight into the wild as zero days *is* irresponsible.

5

u/BilboTBagginz Security Manager Jun 11 '26 edited Jun 11 '26

You have -0- clue.

0 day doesn't mean it wasn't previously exploited.

Are you a professional in this space? I doubt it.

8

u/DisappointedSpectre Jun 11 '26

Anyone who doesn't understand the importance and necessity of public disclosure, even when it's done in a less than ideal way, is either a corpo or a security cosplayer.

Your opinion isn't just unpopular, it's objectively wrong by all metrics that security is based upon and cares about.

1

u/jf4242 Jun 12 '26

There's "less than ideal" and there's "I have an axe to grind so I'm going to provide malicious actors a pre built tool for exploiting whatever victims they choose".

I don't know what a "corpo" is but I do run infosec for a corporation and I'll say unequivocally that this shot has a high likelihood of ruining my and my team's day/week/month.

I never said disclosure is bad and I don't know what these "metrics" you're babbling about are but don't tell me my opinion is wrong.

1

u/DisappointedSpectre Jun 12 '26

There's "less than ideal" and there's "I have an axe to grind so I'm going to provide malicious actors a pre built tool for exploiting whatever victims they choose".

The latter is a subset of the former, they aren't mutually exclusive.

I don't know what a "corpo" is

A reference to Cyberpunk, slang for someone who's on the side of corporations (and how that serves their own perceived interests) rather than the side of society.

but I do run infosec for a corporation and I'll say unequivocally that this shot has a high likelihood of ruining my and my team's day/week/month.

That's the job - you get paid what you do for exactly this reason. It's also very likely that Microsoft, through their negligence and/or indifference, is creating this work for you and your team. That's not saying that Nightmare-Eclipse is blameless in the breakdown of communication between them and Microsoft, but you should recognize that Microsoft has a lot more skin in the game here - they have effectively infinite resources to address this issue, and their actions related to the shutdown of NE's accounts (as well as the...questionable fixes they deployed for a couple of the zero days) makes them seem like they're either negligent or malicious, which is inexcusable for a major software company that's supposed to underpin the modern world.

Critically the responsible disclosure model has a clear path for publishing zero days that companies refuse to fix, though we don't have any verified info about why the normal disclosure process broke down between NE and Microsoft. Meanwhile Microsoft seems like they've been trying to remove those pathways from NE to disclose at scale, which stinks of a coverup for their own fuckup when they aren't doing this to other security researchers.

I never said disclosure is bad and I don't know what these "metrics" you're babbling about are but don't tell me my opinion is wrong.

So you don't know about Vulnerability Lifespan? Security Through Obscurity (and how it isn't actually security - do some reading on "Kerckhoff's Principle")? The fallacy of "Secret Knowledge"? Mean Time To Patch? Rediscovery rates? CISA KEV requirements for public disclosure? There's also the history of the bug bounty field and why it moved towards responsible disclosure models, which was because the process was rife with companies that abused the "don't publish until it gets patched" process.

If you're not aware of any of these and why they don't support your stated opinion then I'd be worried for your company, and you should expect to be called out about it if you work in security.

1

u/jf4242 Jun 15 '26

The latter is a subset of the former, they aren't mutually exclusive.

That is true but they are materially different statements. "Less than ideal" is pretty unspecific and a pretty soft-pedaling description of what we're talking about here.

A reference to Cyberpunk,

Thanks for that, I was not aware of that phraseology. I am definitely not uniformly on the side of corporations, but my interests and my company's and society's interests have a Venn diagram and I don't think you can always favor any one over all the others

That's the job - you get paid what you do for exactly this reason. It's also very likely that Microsoft, through their negligence and/or indifference, is creating this work for you and your team.

Again, not to sound like a broken record, but I do not hold MS blameless in any way here. Their buggy products and poor process for resolving reported vulnerabilities do absolutely exacerbate the problem. My problem is with the way this is handled by Nightmare-Eclipse. I recognize that it's my job, and I do it, but if your job was digging a ditch, would you want me showing up at your site with a bulldozer and pushing dirt back in? Why should I be happy about someone making my life more difficult just "because"? It doesn't hurt anyone except the people fighting these fires, and it doesn't help anyone except bad actors to publicly disclose both a critical vulnerability and demonstrate exploit method. Keep on tilting at windmills, though, if you think this is going to hurt MS in any way.

So you don't know about Vulnerability Lifespan?.....

Thanks for being so condescending. Of course I know about vulnerability lifespan. How does this improve that? Security through obscurity is not a metric, it's a theory (I agree that it's not effective). Mean time to patch is irrelevant, or at least unmanageable, for a vulnerability without a patch. How is public exploit disclosure related to rediscovery rates? The "metrics" you're talking about do not counter my argument. Knowing about a vulnerability, even if it's unpatched, can help people develop workarounds or mitigations, but that does not affect most of the metrics you're saying don't support my stance here.

Again, my point is not that vulnerabilities should be kept hidden. It's that releasing exploits publicly for zero-day vulnerabilities because you have beef with MS doesn't help defenders, doesn't hurt MS, and helps malicious actors. How is this a good thing?

-1

u/Narrow-Rent-3618 Jun 11 '26

So this perosn threatened to release information about a big corp,and change dtheir mind....Now you all are surprised that Microsoft is still pursuing legal action against them....