CVE Tools

Восемь 0-day против Microsoft. Как Nightmare Eclipse превратил раскрытие уязвимостей в личную войну

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedWindowsNightmare EclipseMicrosoft Defender

Our summary

In early 2026, a conflict erupted between hacker Nightmare Eclipse and Microsoft that escalated into a public war over unpatched vulnerabilities. Over several months, Nightmare Eclipse published working exploits for eight previously undisclosed zero-day flaws in Windows, Microsoft Defender, and BitLocker. Some were quickly adopted by threat actors in real-world attacks. The researcher claims his actions were a response to poor treatment from Microsoft’s Security Response Center (MSRC), including ignored reports, withheld bounties, and account suspensions. Microsoft countered that coordinated disclosure was violated, putting users at risk. Among the disclosed bugs is CVE-2026-33825, which allows privilege escalation via local access to the SAM database. Despite patches issued during monthly updates, new exploits followed each fix, creating a cycle of vulnerability exposure and patch evasion.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store