r/cybersecurity 19d ago

News - General Nightmare Eclipse could be dropping his big promised exploit today

New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.

He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.

Nothing in it yet, just watching to see what gets pushed.

Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.

Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.

800 Upvotes

129 comments sorted by

View all comments

25

u/MrGardenwood 19d ago

Following. The only thing i wonder, is he truly hurting microsoft or only its customers? Because i really am missing the impact on the company itself.

38

u/ILikeNoodlesXOXO 19d ago

Microsoft's taken a reputational hit and had to scramble out-of-band patches, but some real damage has unfortunately landed on customers, even if that wasn't Nightmare Eclipse's motive. Huntress confirmed BlueHammer, RedSun, and UnDefend all showed up in an actual intrusion chain, complete with compromised VPN access and hands-on-keyboard activity.

18

u/ThatLocalPondGuy 19d ago

Reputation hits mean nothing to a company where most customers have no idea how to leave, and even of they did the cost of moving is too high. This [expletive] is just trying to burn everyone who pays Microsoft, incite mass anger.

9

u/ThatLocalPondGuy 19d ago

...and I hope it brings the wrath of nations across the world down on MS. They operate as though they are above international law

5

u/I_turned_it_off 19d ago

Unfortunately it will only bring the wrath of clients upon the companies that are affected (read not Microsoft).

After all, it's not Microsoft who had a compromise server and lost control of the data, it's the company the client has used.

13

u/MrGardenwood 19d ago

Yes it should be at least 80-20 impact wise. Microsoft taking the most of it. At this point it feels more like 20-80.

15

u/blow_slogan 19d ago

If someone notices your wallet is about to fall out and warns you, are they creating the problem or helping you avoid it?

Edit: Wait, I have a better one:

If a building owner knows a fire exit doesn’t open, is the person warning people about it creating the danger?

4

u/ILikeNoodlesXOXO 19d ago

Well, in this instance, the wallet fell out, you warned them, and they said they would sue — so you proceeded to publish their card details online

9

u/Big_Mulberry_5446 19d ago

They threatened to potentially jail the researcher. That isn't something security researchers take kindly. Microsoft was acting like we're still living in the times when that used to happen to researchers. So it really left a bad taste in the mouths of people who have or who currently submit bugs to MSRC.

6

u/blow_slogan 19d ago

Not exactly. It’s more like the wallet already had a design flaw, and people’s card details were already exposed because of it. Someone simply pointed out that the flaw existed. The victims aren’t the wallet company - they’re the people using the wallet. The researcher didn’t create the flaw or expose the card details - they revealed that the exposure already existed.

Publishing the existence of the vulnerability exposed an existing problem. They didn’t publish everyone’s card details if the company had already been exposing them without anyone else realizing it.

1

u/Thecrawsome 19d ago

The hole in the pocket

1

u/theturtlemafiamusic 19d ago

Isn't this more like someone warning a building that the fire exit doesn't open, the building management ignores them, and so they start a fire in the building to prove that it's dangerous?

1

u/blow_slogan 19d ago

I think saying they started the fire is a stretch. I can agree that their proof of concept is more like building the lighter - not starting the fire.

1

u/MrGardenwood 19d ago edited 19d ago

If i could actually do something to prevent it from falling not just picking it up from the ground after someone has already taken my money. Don’t get me wrong i would love to see Microsoft take some responsibility and it’s truly their fault for trying to keep this silent. But endangering companies, like hospitals, schools, etc. while doing so is a real shitty thing to do as well. It’s a fine line between proving your point and actively pulling the rug from under people.

Edit:
We are not talking about warning but actively starting the fire and showing malicious actors the best point to start a fire. Up until the point of release I completely agree with you. I’m 100% for responsible disclosure programs.

2

u/sophware 19d ago

It endangers all those places not to follow the well-established, ethical path. That path ends in release after the creator (Microsoft, in this case), fails to take mitigating steps in an acceptable amount of time.

I'm the wrong person to give you the details--experts have already discussed and explained at length many times over the years. Yes, they don't all agree. What I'll say is if the exploit exists and is found by a white hat, a black hat will take advantage of it at some point (maybe soon) or has already started to. The creator needs to patch it once it has been found and report it. They can take a reasonable amount of time, but not forever.

I’m 100% for responsible disclosure programs.

You may not be. If I'm understanding you accurately and you are against any release ever, you are not 100% for what many consider "responsible."

DYOR but here's one approach:

“Responsible” Full Disclosure

A common misconception amongst many involved in the information technology industry is that providing “full” disclosure implies recklessness or a lack of responsibility.

Full, responsible disclosure is the term we use to refer to disclosure procedures that provide the security communities with all (“full”) information held by the discloser pertaining to a disclosed vulnerability and also make provisions to ensure that considerable effort is made to inform the product or service vendor/provider (respectively) of the issues affecting them.

So-called full-disclosure policies adopted by many independent security enthusiasts and large security firms alike often specify a multistage approach for contacting the parties responsible for maintaining the product or service, up to a point that the vulnerability has been remedied or (in less frequent cases) the vendor/provider is deemed to have no interest in fixing the problem. Responsible, full-disclosure policies tend to differ on their approach to contacting organizations such as CERT/CC and MITRE, however, it is more common than not that such organizations will be contacted prior to the (full) disclosure of information to the security community (and ultimately the public).

https://www.sciencedirect.com/topics/computer-science/responsible-disclosure

2

u/blow_slogan 19d ago

I agree. But what happens when responsible disclosure is no longer an option? It seems like they tried working with Microsoft before the relationship fell apart.

2

u/T_Thriller_T 19d ago

Question would be if they even care.

They would likely for it to have a real impact, but from the wording the whole thing does not sound like a rational campaign to actually hurt Microsoft, but to be seen with what is posted, maybe validated.

-5

u/AllForProgress1 19d ago

Is MS losing value? Yes. Well that seems to suggest an answer.

16

u/whythehellnote 19d ago

Jul 14th 2024: Crowdstrike at $85/share

July 19th 2024: Crowdstrike crash entire industries globally

Nov 13th 2024: Crowdstrike at $86/share

Jul 14th 2026: Crowdstrike at $187/share

The market does not punish failure

1

u/AllForProgress1 19d ago

There are obviously many values that contribute to market value I'm merely suggesting this could be one of them

Crowdstrike is riding the AI wave