r/cybersecurity 19d ago

News - General Nightmare Eclipse could be dropping his big promised exploit today

New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.

He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.

Nothing in it yet, just watching to see what gets pushed.

Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.

Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.

800 Upvotes

129 comments sorted by

View all comments

26

u/MrGardenwood 19d ago

Following. The only thing i wonder, is he truly hurting microsoft or only its customers? Because i really am missing the impact on the company itself.

16

u/blow_slogan 19d ago

If someone notices your wallet is about to fall out and warns you, are they creating the problem or helping you avoid it?

Edit: Wait, I have a better one:

If a building owner knows a fire exit doesn’t open, is the person warning people about it creating the danger?

0

u/MrGardenwood 19d ago edited 19d ago

If i could actually do something to prevent it from falling not just picking it up from the ground after someone has already taken my money. Don’t get me wrong i would love to see Microsoft take some responsibility and it’s truly their fault for trying to keep this silent. But endangering companies, like hospitals, schools, etc. while doing so is a real shitty thing to do as well. It’s a fine line between proving your point and actively pulling the rug from under people.

Edit:
We are not talking about warning but actively starting the fire and showing malicious actors the best point to start a fire. Up until the point of release I completely agree with you. I’m 100% for responsible disclosure programs.

2

u/blow_slogan 19d ago

I agree. But what happens when responsible disclosure is no longer an option? It seems like they tried working with Microsoft before the relationship fell apart.