A single security researcher has upended assumptions about coordinated disclosure. In just six weeks this researcher, known as Nightmare-Eclipse or Chaotic Eclipse, dropped working proof-of-concept code for six Windows vulnerabilities. Three saw immediate use in real intrusions. Microsoft calls the actions irresponsible. The researcher says Redmond started the fight.
The Grudge That Launched a Campaign
Nightmare-Eclipse claims prior attempts to report flaws through official channels ended in dismissal, account deletion and public humiliation. “I never wanted to reopen a blog and a new github account to drop code,” the researcher wrote on a personal blog. “But someone violated our agreement and left me homeless with nothing.”
That personal stake turned technical. Starting in early April 2026 the researcher released exploits one after another. BlueHammer. RedSun. UnDefend. Then YellowKey, GreenPlasma and MiniPlasma. Some targeted Windows Defender itself. Others hit BitLocker or privilege boundaries. The pace was relentless. So was the impact.
Attackers wasted no time. Huntress spotted BlueHammer, RedSun and UnDefend deployed inside a live intrusion by mid-April. The attackers had first compromised a FortiGate SSL VPN. From there they staged binaries in user-writable folders such as Pictures and Downloads. They ran reconnaissance commands. whoami /priv. cmdkey /list. net group. The tools didn’t all succeed in that particular case. But their presence signaled a new reality. Public zero-day code moves fast.
BlueHammer, tracked as CVE-2026-33825, abuses a race condition in Windows Defender’s update and remediation process. It leverages Volume Shadow Copy to redirect file operations. The result? A standard user gains NT AUTHORITY\SYSTEM rights. Microsoft patched it in April. RedSun and UnDefend followed similar logic yet used different code paths. One hijacks the Storage Tiers Management Engine. The other locks Defender update files to blind protection. Microsoft later assigned CVE-2026-41091 to RedSun and CVE-2026-45498 to UnDefend.
YellowKey, CVE-2026-45585, takes a different angle. It bypasses BitLocker on systems using TPM-only configurations. Physical access becomes enough to read protected volumes. Microsoft has labeled exploitation of YellowKey more likely. Patches for it, GreenPlasma and MiniPlasma remain unavailable as of late May. MiniPlasma reuses a flaw first reported years ago. It still elevates privileges on fully updated Windows 11 systems.
But the technical details matter less than the pattern. One person. Six exploits. No advance warning to Microsoft. Repositories posted on GitHub, then banned, then moved to GitLab, then banned again. The researcher has promised more. A “bone shattering” release on July 14. Remote code execution bugs are on the table. So is a dead man’s switch.
Microsoft responded on May 28 with a blog post titled “A Shared Responsibility: Protecting Customers Through Coordinated Vulnerability Disclosure.” The company stated the six flaws “were not responsibly disclosed.” It emphasized that public proof-of-concept code for unpatched bugs “are never justifiable and have real-world consequences.” Redmond has disabled the researcher’s MSRC account. It has signaled possible involvement of its Digital Crimes Unit. Legal action is on the table.
The researcher fired back. “So let me get this straight, when I actively asked you to communicate with me, you refused, humiliated me, and made sure to insult me in front of people,” the May blog post read. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”
Security voices outside both parties have raised sharp questions. Kevin Beaumont, writing on DoublePulsar, called Microsoft’s stance troubling. In coverage by The Verge, Beaumont noted the difficulty of responsible reporting once banned. He added, “If Microsoft’s tactic is to try to criminalise not following often arbitrary ‘responsible disclosure’ frameworks, good luck defending that in court — because there’s a whole clown car of prior decision making within Microsoft and facts which would emerge in that process.”
History complicates the company’s position. Microsoft has hired researchers who once published exploits publicly. It has bought vulnerabilities from brokers. It has employed individuals with past criminal hacking convictions. Those facts now sit beside threats of prosecution against Nightmare-Eclipse.
Defenders face immediate pressure. Organizations must scan for the known binaries. FunnyApp.exe. RedSun.exe. undef.exe. Look in Pictures, Downloads and other writable paths. Monitor for the reconnaissance commands attackers favor. Review VPN logs for suspicious access patterns. And patch what is available. CVE-2026-33825 is fixed. Others are not.
The broader message is uncomfortable. A motivated individual with deep platform knowledge can force emergency patches, expose architectural weaknesses and spark a public feud that damages trust. Microsoft says coordinated disclosure protects users. The researcher says the process failed first. Both claims carry weight. Neither fully resolves the tension.
Three of the six flaws already appear in active attacks. More code is coming. July 14 looms. Enterprises cannot wait for perfect process. They must assume the next exploit will surface without notice. And they must build defenses that do not rely solely on any single vendor’s update cycle. The Nightmare has only begun.


WebProNews is an iEntry Publication