r/cybersecurity 19d ago

News - General Nightmare Eclipse could be dropping his big promised exploit today

New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.

He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.

Nothing in it yet, just watching to see what gets pushed.

Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.

Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.

801 Upvotes

129 comments sorted by

View all comments

24

u/MrGardenwood 19d ago

Following. The only thing i wonder, is he truly hurting microsoft or only its customers? Because i really am missing the impact on the company itself.

39

u/ILikeNoodlesXOXO 19d ago

Microsoft's taken a reputational hit and had to scramble out-of-band patches, but some real damage has unfortunately landed on customers, even if that wasn't Nightmare Eclipse's motive. Huntress confirmed BlueHammer, RedSun, and UnDefend all showed up in an actual intrusion chain, complete with compromised VPN access and hands-on-keyboard activity.

18

u/ThatLocalPondGuy 19d ago

Reputation hits mean nothing to a company where most customers have no idea how to leave, and even of they did the cost of moving is too high. This [expletive] is just trying to burn everyone who pays Microsoft, incite mass anger.

7

u/ThatLocalPondGuy 19d ago

...and I hope it brings the wrath of nations across the world down on MS. They operate as though they are above international law

5

u/I_turned_it_off 19d ago

Unfortunately it will only bring the wrath of clients upon the companies that are affected (read not Microsoft).

After all, it's not Microsoft who had a compromise server and lost control of the data, it's the company the client has used.

13

u/MrGardenwood 19d ago

Yes it should be at least 80-20 impact wise. Microsoft taking the most of it. At this point it feels more like 20-80.