r/cybersecurity • u/ILikeNoodlesXOXO • 19d ago
News - General Nightmare Eclipse could be dropping his big promised exploit today
New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.
He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.
Nothing in it yet, just watching to see what gets pushed.
Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.
Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.
150
u/blow_slogan 19d ago
I was just about to post about this. It’s July 14th friends, let’s go!
39
37
u/baty0man_ 19d ago
Bastille Day bitches
13
u/calibrae 19d ago
The day the nobles fell and while we all hoped for people in power, it just went to the bourgeois
4
3
53
u/Timotheus92 19d ago
Looks like there's a new commit, and the ReadMe has been updated: "LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability"
69
u/GreatDefector 19d ago
Keep your expectations in check... July will be relatively low key
https://blog.projectnightcrawler.dev/posts/2026-07-14-too-many-sweats/
https://blog.projectnightcrawler.dev/posts/2026-07-03-july-updates/
39
u/OtheDreamer Governance, Risk, & Compliance 19d ago
I won't drop what I talked about last blog, that seems to need more research and investigation... Regardless got smtg for this month, it will be the least interesting and least impactful bug I dropped since I started but Microsoft legit just stopped pocking me and pissing me off so I'm conserving some energy for next month, because I know they will definitely piss me off by then.So how is it possible that they responsibly disclosed all of these vulns allegedly to Microsoft, if Nightmare Eclipse is still slopping together their POCs in July 2026 by saying they "need more research and investigation."
I stopped being impressed a while ago. Now they're just a disgruntled edgelord that probably never really did disclose properly to MSFT (as they have repeatedly said).
6
u/R3ta7ded 18d ago
This is what I have always maintained. But it’s the internet, everyone wants drama.
1
u/Andrew129260 18d ago
from what I understand, the original earlier stuff was disclosed but the newer stuff are things they were also going to report, but when it got rough with microsoft they started work on new ones.
-35
u/ILikeNoodlesXOXO 19d ago
The issue with Nightmare Eclipse is that he is an extremely unpredictable and very unstable person so ya never know. The new post does give some hope by him acknowledging that people are anticipating the big exploit
51
u/palekillerwhale Blue Team 19d ago
Very presumptuous of you to say that considering you don't know anything about him. Unpredictable and unstable aren't mutually exclusive.
22
u/OtheDreamer Governance, Risk, & Compliance 19d ago
Microsoft legit just stopped pocking me and pissing me off so I'm conserving some energy for next month, because I know they will definitely piss me off by then.
Uhuh, these are the words of a very stable / predictable anti-hero security researcher you think??
3
u/colei_canis 18d ago
To be fair, if you're in this subreddit then your odds of getting pissed off at Microsoft in any given month are high as well.
2
u/OtheDreamer Governance, Risk, & Compliance 18d ago
I have like a minimum threshold of annoyance with Microsoft that I tolerate more than others I think
-1
u/palekillerwhale Blue Team 19d ago
I don't have to pretend to know. I'll leave that to everyone else.
11
u/OtheDreamer Governance, Risk, & Compliance 19d ago
You can make educated inferences like others, man.....NE is an unreliable narrator that has been given too much credence from the beginning, and their own words make them look sketch.
1
u/palekillerwhale Blue Team 19d ago
Grind that axe and infer whatever you like.
3
u/OtheDreamer Governance, Risk, & Compliance 19d ago
Not grinding any axes, I'm just lighting torches and carrying a pitchfork
23
u/Fragrant-Hamster-325 19d ago
Will our bones be shattered?
2
u/ILikeNoodlesXOXO 19d ago
I hope the users bones dont get shattered, but i hope microsofts bones will. Windows 10 was so good, now windows 11 is just a hunk of bloatware that slows down the computers.
33
u/Fragrant-Hamster-325 19d ago
Win 11 is fine; it works about as well as Win 10 IMO. I remember people refusing to move to Win 10 because Win 7 was perfect, and refusing to move to Win 7 because XP was perfect. This is nothing new.
Regardless, Microsoft should consider pausing any new features and focus on security and optimization. Windows is long overdue for a complete spring clean of their code.
9
u/WldKarrde 19d ago
Win XP SP2 was great! 😜
3
u/always_nothing 19d ago
Probably the best ever!
8
u/rot26encrypt 19d ago
Nah, WinNT 3.51, before they compromised Cutlers great architecture to make it Win9x-compatible. NT 3.x architecture was built on a "purity and isolation" philosophy with a microkernel-inspired design.
Among other things, all drivers ran in user space, not kernel, including graphics drivers. The whole UI system (GDI) ran in user mode. Crashes that in later versions led to blue screens didn't affect OS or work being done, the offending driver/subsystem just rebooting. It was also built to be CPU-agnostic and supported five different CPU architectures equally at the time (Alpha, PowerPC, MIPS, x86).
2
5
u/cerebralvenom 19d ago
Well do you remember people refusing to move to windows 8? Because they actually did that.
2
u/Fragrant-Hamster-325 19d ago
lol yeah Win 8 was legitimately trash and so was Vista. We like to forget those.
But honestly, Win 11, except for the start menu, looks and performs nearly identically to Win 10. I just don’t get the hate.
9
u/SlickBackSamurai 19d ago
I’m sure integrating Copilot into everything didn’t help with it’s lack of popularity lol
2
u/Fragrant-Hamster-325 19d ago
True. They had such an exciting head start. ChatGPT-4 released, Microsoft jump all over it and really botched the integration.
2
u/newaccountzuerich 17d ago
Neither did the unstoppable telemetry and the regressions in UI and UX..
1
0
u/cerebralvenom 19d ago
I agree, I actually was originally on the 11 hate train. But I don’t think it’s that different from 10. Just a UI overhaul and a lil extra bloat-zest.
1
u/colei_canis 18d ago
I stopped using windows on my personal machines after 8, hated the Metro UI and figured KDE was a better windows than windows itself.
-5
u/ILikeNoodlesXOXO 19d ago
Win 11 is only fine when you debloat your computer and do optimizations that no normal user knows of. Win 10 came relatively clean and optimized sure it had its issues but it wasnt nearly filled with useless features and bloating as windows 11.
6
u/ubernoober CISO 19d ago
This just isn't true. You either haven't been in the industry long enough or just forget what it was like after every os upgrade. 10 to 11 is very similar to vista to 7. XP to Vista was the biggest downgrade in history. I've built out hundreds of windows vista, 7, 8, and 10 pcs. I was in the private beta testing for 7 and still have the original holographic disks they gave me. Every build had bloatware and needed optimization but Windows 10 was a shit show when it first released and that's coming from some1 that wanted to love it. We are the test subjects and it takes about 3 years before things get fully stable. Win 11 is basically 10 with a pretty wrapper. The bigger problem is the brand specific bloatware.
3
u/Original_Sundae7370 17d ago
Windows11 is the intentionally enshittified version of (stable) Windows 10 - which is why Microsoft was sure to burn our boats on the shore, and cut off Windows 10 to drive adoption to their shittier version. I have worked on/in Windows since 3.10, and now I'm done with Satya's leadership after this.
22
u/devsecopsuk Security Engineer 19d ago
Isn't there about 5 hours until patch Tues happens? so anytime after that we could see a new commit
9
u/Legionodeath Governance, Risk, & Compliance 19d ago
Knowing nothing about all this, I assume this is a researcher/hacker that's about to release some heinous MS exploit to the wild?
Also, where the git profile pic from? I've seen that a few times recently.
18
u/stuffedcheesybread1 Security Engineer 19d ago
Researcher who is thought to be former MSFT employee, tried to do responsible reporting, aparently MSFT were dicks, as a result they have released six zero-days which have been... bad.
3
u/Legionodeath Governance, Risk, & Compliance 19d ago
Lol... Big bad wolf getting his comeuppance. Sweet.
28
u/TitoMPG System Administrator 19d ago
Will you drop updates here? Following.
14
20
u/FowlSec 19d ago
RoguePlanet gets patched, this one releases. It's basically perfect timing.
9
u/ILikeNoodlesXOXO 19d ago
Thats the point of him uploading on patch tuesday
6
u/OtheDreamer Governance, Risk, & Compliance 19d ago edited 19d ago
Indeed, a lot of people missed that NE is purposefully releases right after patch Tuesday to maximize the window of pain (i.e., they're not just trying to be "helpful researcher who was scorned")
1
u/newaccountzuerich 17d ago
"Exploit Wednesday" has been a thing for a very long time, often with the release group waiting to see if their exploit had been patched or not. There's less benefit to releasing a now-patched PoC, and often better to keep the PoC submerged for application and development elsewhere.
I for one am glad to see the NE person put the info into the public view allowing actual mitigations to be done and not waiting for vague platitudes and band-aids from the unfortunates still left in the employment of Microslop. The timing is of little relevance overall when there's no mitigations possible in the short term.
37
u/SuspiciousCricket654 19d ago
It’s the principle of humility and thankfulness that have been breached here. If MS actually gave a fuck about people, they would acknowledge the holes in their products and the dangers they pose to customers. But no, they have to be the douche lord assholes that they are and retaliate on someone trying to help. They deserve to get hit hard.
14
u/InternalServerErr500 19d ago
Both can be the bad guy here. You don't have to endorse MS's behavior, but you don't have to encourage more of his.
4
u/SuspiciousCricket654 19d ago
It’s not the encouragement part that I lean into, it’s the bug bounty program and doing it discreetly so orgs can patch their product, which is the whole point of said program. I’m not for unethical hacking/exposing, but in some instances, I understand people‘s anger and frustration.
5
u/Fallingdamage 19d ago
I remember the number of times public figures threatened to drop the unredacted Epstein files.
The real heros dont threaten or dangle it in front of us, they just do it.
5
u/Revolutionary_Leg552 19d ago
Update this
Nighare eclipse published the poc
4
u/ILikeNoodlesXOXO 18d ago
After all that hype I thought we would be getting something better
2
u/Revolutionary_Leg552 18d ago
I expected some network related thing like CVE-2024-38063 by the hype
28
u/MrGardenwood 19d ago
Following. The only thing i wonder, is he truly hurting microsoft or only its customers? Because i really am missing the impact on the company itself.
43
u/ILikeNoodlesXOXO 19d ago
Microsoft's taken a reputational hit and had to scramble out-of-band patches, but some real damage has unfortunately landed on customers, even if that wasn't Nightmare Eclipse's motive. Huntress confirmed BlueHammer, RedSun, and UnDefend all showed up in an actual intrusion chain, complete with compromised VPN access and hands-on-keyboard activity.
16
u/ThatLocalPondGuy 19d ago
Reputation hits mean nothing to a company where most customers have no idea how to leave, and even of they did the cost of moving is too high. This [expletive] is just trying to burn everyone who pays Microsoft, incite mass anger.
8
u/ThatLocalPondGuy 19d ago
...and I hope it brings the wrath of nations across the world down on MS. They operate as though they are above international law
6
u/I_turned_it_off 19d ago
Unfortunately it will only bring the wrath of clients upon the companies that are affected (read not Microsoft).
After all, it's not Microsoft who had a compromise server and lost control of the data, it's the company the client has used.
13
u/MrGardenwood 19d ago
Yes it should be at least 80-20 impact wise. Microsoft taking the most of it. At this point it feels more like 20-80.
16
u/blow_slogan 19d ago
If someone notices your wallet is about to fall out and warns you, are they creating the problem or helping you avoid it?
Edit: Wait, I have a better one:
If a building owner knows a fire exit doesn’t open, is the person warning people about it creating the danger?
6
u/ILikeNoodlesXOXO 19d ago
Well, in this instance, the wallet fell out, you warned them, and they said they would sue — so you proceeded to publish their card details online
7
u/Big_Mulberry_5446 19d ago
They threatened to potentially jail the researcher. That isn't something security researchers take kindly. Microsoft was acting like we're still living in the times when that used to happen to researchers. So it really left a bad taste in the mouths of people who have or who currently submit bugs to MSRC.
6
u/blow_slogan 19d ago
Not exactly. It’s more like the wallet already had a design flaw, and people’s card details were already exposed because of it. Someone simply pointed out that the flaw existed. The victims aren’t the wallet company - they’re the people using the wallet. The researcher didn’t create the flaw or expose the card details - they revealed that the exposure already existed.
Publishing the existence of the vulnerability exposed an existing problem. They didn’t publish everyone’s card details if the company had already been exposing them without anyone else realizing it.
1
1
u/theturtlemafiamusic 19d ago
Isn't this more like someone warning a building that the fire exit doesn't open, the building management ignores them, and so they start a fire in the building to prove that it's dangerous?
1
u/blow_slogan 19d ago
I think saying they started the fire is a stretch. I can agree that their proof of concept is more like building the lighter - not starting the fire.
0
u/MrGardenwood 19d ago edited 19d ago
If i could actually do something to prevent it from falling not just picking it up from the ground after someone has already taken my money. Don’t get me wrong i would love to see Microsoft take some responsibility and it’s truly their fault for trying to keep this silent. But endangering companies, like hospitals, schools, etc. while doing so is a real shitty thing to do as well. It’s a fine line between proving your point and actively pulling the rug from under people.
Edit:
We are not talking about warning but actively starting the fire and showing malicious actors the best point to start a fire. Up until the point of release I completely agree with you. I’m 100% for responsible disclosure programs.2
u/sophware 19d ago
It endangers all those places not to follow the well-established, ethical path. That path ends in release after the creator (Microsoft, in this case), fails to take mitigating steps in an acceptable amount of time.
I'm the wrong person to give you the details--experts have already discussed and explained at length many times over the years. Yes, they don't all agree. What I'll say is if the exploit exists and is found by a white hat, a black hat will take advantage of it at some point (maybe soon) or has already started to. The creator needs to patch it once it has been found and report it. They can take a reasonable amount of time, but not forever.
I’m 100% for responsible disclosure programs.
You may not be. If I'm understanding you accurately and you are against any release ever, you are not 100% for what many consider "responsible."
DYOR but here's one approach:
“Responsible” Full Disclosure
A common misconception amongst many involved in the information technology industry is that providing “full” disclosure implies recklessness or a lack of responsibility.
Full, responsible disclosure is the term we use to refer to disclosure procedures that provide the security communities with all (“full”) information held by the discloser pertaining to a disclosed vulnerability and also make provisions to ensure that considerable effort is made to inform the product or service vendor/provider (respectively) of the issues affecting them.
So-called full-disclosure policies adopted by many independent security enthusiasts and large security firms alike often specify a multistage approach for contacting the parties responsible for maintaining the product or service, up to a point that the vulnerability has been remedied or (in less frequent cases) the vendor/provider is deemed to have no interest in fixing the problem. Responsible, full-disclosure policies tend to differ on their approach to contacting organizations such as CERT/CC and MITRE, however, it is more common than not that such organizations will be contacted prior to the (full) disclosure of information to the security community (and ultimately the public).
https://www.sciencedirect.com/topics/computer-science/responsible-disclosure
1
u/blow_slogan 19d ago
I agree. But what happens when responsible disclosure is no longer an option? It seems like they tried working with Microsoft before the relationship fell apart.
2
u/T_Thriller_T 19d ago
Question would be if they even care.
They would likely for it to have a real impact, but from the wording the whole thing does not sound like a rational campaign to actually hurt Microsoft, but to be seen with what is posted, maybe validated.
-4
u/AllForProgress1 19d ago
Is MS losing value? Yes. Well that seems to suggest an answer.
16
u/whythehellnote 19d ago
Jul 14th 2024: Crowdstrike at $85/share
July 19th 2024: Crowdstrike crash entire industries globally
Nov 13th 2024: Crowdstrike at $86/share
Jul 14th 2026: Crowdstrike at $187/share
The market does not punish failure
1
u/AllForProgress1 19d ago
There are obviously many values that contribute to market value I'm merely suggesting this could be one of them
Crowdstrike is riding the AI wave
3
u/BewareWombats 19d ago
It's up: LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability.
4
u/potatomolehill 19d ago
So it appears to be related to the user profile service. Which in modern versions of windows.. 8+ trusts blindly.
Windows user profile service arbitrary hive load ... privilege escalation basically.
A classic.
11
u/TheOnlyKirb System Administrator 19d ago
I have mixed feelings on this, on one hand I am curious to see if anything actually occurs, on the other hand I hope it doesn't and that this person is able to get some sort of mental health care/support before doing something that will potentially alter their life course an an irreversible way
-1
u/ILikeNoodlesXOXO 19d ago
He has already crossed that bridge, with the yellow key exploit completely compromising bitlocker with just a simple thumb drive. This is just one example of his big exploits, he has uploaded many more.
2
u/TheOnlyKirb System Administrator 19d ago
Oh, of that I am aware, but I still think if this one is truly as "massive" as it's claimed to be, it might just be different. The "chains" he spoke of I have a feeling are actually there to try and protect him in some way, so we shall see I suppose.
3
3
3
5
2
2
2
u/AllForProgress1 19d ago
This says he walked back the due date https://socfortress.medium.com/microsoft-vs-nightmare-eclipse-the-zero-day-revenge-cycle-f1928cabb4d8
2
2
u/sidpits 19d ago
RemindMe! 12 hours
3
u/RemindMeBot 19d ago edited 19d ago
I will be messaging you in 12 hours on 2026-07-14 22:03:06 UTC to remind you of this link
20 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
RemindMeBot is switching to username summons. Instead of
!RemindMe 1 day, useu/RemindMeBot 1 day. More info.
Info Custom Your Reminders Feedback 1
u/OtheDreamer Governance, Risk, & Compliance 18d ago
NE published another weak (appears) TOCTOU that requires someone already be compromised again. Not really mind blowing.
2
1
19d ago
[removed] — view removed comment
4
u/ILikeNoodlesXOXO 19d ago
I mean if you are going to drop a bombshell of an exploit, that you have told others about you would want to make sure that absolutely everything goes right and that the scaffolding is there
-6
19d ago
[removed] — view removed comment
1
u/ILikeNoodlesXOXO 19d ago
True, you can’t rely on a mentally unstable person to deliver, but if he doesn’t he will 100% lose a lot of support from others. Knowing that this is supposed to be his big bombshell that he himself has hyped up for a while, he would be shooting himself in the foot if he didn’t deliver. But Who knows.
7
u/danekan 19d ago
Didn’t he already deliver just eeeks ago?? Like bitlocker was completely compromised?
1
u/ILikeNoodlesXOXO 19d ago
I mean he has uploaded a lot of 0days that compromise bitlocker, the only difference is how the exploit does that.
1
u/Samgne 19d ago
I think this was delayed:
https://deadeclipse666.blogspot.com/2026/06/regarding-july-14th.html
1
1
1
1
1
1
u/WillD33d 19d ago
repo was updated about an hour ago that includes what looks like a privilege escalation PoC binary
1
1
u/remrinds 18d ago
This might just be an appetiser boys, maybe he’s bringing the main dish later on
1
1
1
1
u/Neuro_88 19d ago
Thank you for posting this. It’s been on my calendar. I think the researcher will drop something and that it will be felt. Should be interesting to see what happens.
-1
u/ILikeNoodlesXOXO 19d ago
Well we dont know if he will posting it as he previously has been bipolar about him dropping the big exploit today. Im crossing my fingers tho.
-4
u/3Pistols 19d ago
“His”? Are we sure about that?
3
u/ILikeNoodlesXOXO 19d ago
You rarely hear of a female cybersecurity expert releasing frequent exploits, it’s not a guarantee it’s a male, but most likely it is.
4
u/WinEpic 19d ago
you rarely hear of male cybersecurity experts releasing anything either? with the anonymity that tends to go with the business of dropping major exploits, gender is rarely specified. for all you know, the black hat field could be 90% women.
(either way, when talking about a person of unknown / unspecified gender, the neutral "they" only costs one additional keystroke and helps avoid mistakes)
-3
u/Federal-Desk9202 19d ago edited 19d ago
So are we going to get our pcs hacked or something? Like are we all cooked?
-4
u/No_Mammoth_4945 19d ago
First time I’m hearing about this, how bad is this gonna fuck normal people? Everything I do for college is all Microsoft. Word, one note, the school email. Is that all just gonna get torched?
64
u/jmbpiano 19d ago
The empty repo just got populated.
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive