Microsoft’s Nightmare: One Researcher, Six Windows Zero-Days and a Feud That Won’t End

One researcher released six Windows zero-day exploits in six weeks after a dispute with Microsoft. Three are already exploited in real intrusions. The feud now includes account bans, legal threats and promises of more severe drops. Enterprises face immediate risks from unpatched flaws in Defender, BitLocker and privilege mechanisms.
Microsoft’s Nightmare: One Researcher, Six Windows Zero-Days and a Feud That Won’t End
Written by Juan Vasquez

A single security researcher has upended assumptions about coordinated disclosure. In just six weeks this researcher, known as Nightmare-Eclipse or Chaotic Eclipse, dropped working proof-of-concept code for six Windows vulnerabilities. Three saw immediate use in real intrusions. Microsoft calls the actions irresponsible. The researcher says Redmond started the fight.

The Grudge That Launched a Campaign

Nightmare-Eclipse claims prior attempts to report flaws through official channels ended in dismissal, account deletion and public humiliation. “I never wanted to reopen a blog and a new github account to drop code,” the researcher wrote on a personal blog. “But someone violated our agreement and left me homeless with nothing.”

That personal stake turned technical. Starting in early April 2026 the researcher released exploits one after another. BlueHammer. RedSun. UnDefend. Then YellowKey, GreenPlasma and MiniPlasma. Some targeted Windows Defender itself. Others hit BitLocker or privilege boundaries. The pace was relentless. So was the impact.

Attackers wasted no time. Huntress spotted BlueHammer, RedSun and UnDefend deployed inside a live intrusion by mid-April. The attackers had first compromised a FortiGate SSL VPN. From there they staged binaries in user-writable folders such as Pictures and Downloads. They ran reconnaissance commands. whoami /priv. cmdkey /list. net group. The tools didn’t all succeed in that particular case. But their presence signaled a new reality. Public zero-day code moves fast.

BlueHammer, tracked as CVE-2026-33825, abuses a race condition in Windows Defender’s update and remediation process. It leverages Volume Shadow Copy to redirect file operations. The result? A standard user gains NT AUTHORITY\SYSTEM rights. Microsoft patched it in April. RedSun and UnDefend followed similar logic yet used different code paths. One hijacks the Storage Tiers Management Engine. The other locks Defender update files to blind protection. Microsoft later assigned CVE-2026-41091 to RedSun and CVE-2026-45498 to UnDefend.

YellowKey, CVE-2026-45585, takes a different angle. It bypasses BitLocker on systems using TPM-only configurations. Physical access becomes enough to read protected volumes. Microsoft has labeled exploitation of YellowKey more likely. Patches for it, GreenPlasma and MiniPlasma remain unavailable as of late May. MiniPlasma reuses a flaw first reported years ago. It still elevates privileges on fully updated Windows 11 systems.

But the technical details matter less than the pattern. One person. Six exploits. No advance warning to Microsoft. Repositories posted on GitHub, then banned, then moved to GitLab, then banned again. The researcher has promised more. A “bone shattering” release on July 14. Remote code execution bugs are on the table. So is a dead man’s switch.

Microsoft responded on May 28 with a blog post titled “A Shared Responsibility: Protecting Customers Through Coordinated Vulnerability Disclosure.” The company stated the six flaws “were not responsibly disclosed.” It emphasized that public proof-of-concept code for unpatched bugs “are never justifiable and have real-world consequences.” Redmond has disabled the researcher’s MSRC account. It has signaled possible involvement of its Digital Crimes Unit. Legal action is on the table.

The researcher fired back. “So let me get this straight, when I actively asked you to communicate with me, you refused, humiliated me, and made sure to insult me in front of people,” the May blog post read. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”

Security voices outside both parties have raised sharp questions. Kevin Beaumont, writing on DoublePulsar, called Microsoft’s stance troubling. In coverage by The Verge, Beaumont noted the difficulty of responsible reporting once banned. He added, “If Microsoft’s tactic is to try to criminalise not following often arbitrary ‘responsible disclosure’ frameworks, good luck defending that in court — because there’s a whole clown car of prior decision making within Microsoft and facts which would emerge in that process.”

History complicates the company’s position. Microsoft has hired researchers who once published exploits publicly. It has bought vulnerabilities from brokers. It has employed individuals with past criminal hacking convictions. Those facts now sit beside threats of prosecution against Nightmare-Eclipse.

Defenders face immediate pressure. Organizations must scan for the known binaries. FunnyApp.exe. RedSun.exe. undef.exe. Look in Pictures, Downloads and other writable paths. Monitor for the reconnaissance commands attackers favor. Review VPN logs for suspicious access patterns. And patch what is available. CVE-2026-33825 is fixed. Others are not.

The broader message is uncomfortable. A motivated individual with deep platform knowledge can force emergency patches, expose architectural weaknesses and spark a public feud that damages trust. Microsoft says coordinated disclosure protects users. The researcher says the process failed first. Both claims carry weight. Neither fully resolves the tension.

Three of the six flaws already appear in active attacks. More code is coming. July 14 looms. Enterprises cannot wait for perfect process. They must assume the next exploit will surface without notice. And they must build defenses that do not rely solely on any single vendor’s update cycle. The Nightmare has only begun.

Subscribe for Updates

SecurityProNews Newsletter

News, updates and trends in IT security.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us