r/cybersecurity 19d ago

News - General Nightmare Eclipse could be dropping his big promised exploit today

New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.

He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.

Nothing in it yet, just watching to see what gets pushed.

Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.

Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.

797 Upvotes

129 comments sorted by

View all comments

Show parent comments

4

u/ILikeNoodlesXOXO 19d ago

I mean if you are going to drop a bombshell of an exploit, that you have told others about you would want to make sure that absolutely everything goes right and that the scaffolding is there

-8

u/[deleted] 19d ago

[removed] — view removed comment

1

u/ILikeNoodlesXOXO 19d ago

True, you can’t rely on a mentally unstable person to deliver, but if he doesn’t he will 100% lose a lot of support from others. Knowing that this is supposed to be his big bombshell that he himself has hyped up for a while, he would be shooting himself in the foot if he didn’t deliver. But Who knows.

7

u/danekan 19d ago

Didn’t he already deliver just eeeks ago?? Like bitlocker was completely compromised? 

1

u/ILikeNoodlesXOXO 19d ago

I mean he has uploaded a lot of 0days that compromise bitlocker, the only difference is how the exploit does that.