CVE Tools
Back to feed
Exploited in the wild Windows Nightmare Eclipse zero-day Microsoft Defender Microsoft

Восемь 0-day против Microsoft. Как Nightmare Eclipse превратил раскрытие уязвимостей в личную войну

Хакер (xakep.ru)·By Мария Нефёдова··3 min read
CVE Tools coverage

In early 2026, a conflict erupted between hacker Nightmare Eclipse and Microsoft that escalated into a public war over unpatched vulnerabilities. Over several months, Nightmare Eclipse published working exploits for eight previously undisclosed zero-day flaws in Windows, Microsoft Defender, and BitLocker. Some were quickly adopted by threat actors in real-world attacks. The researcher claims his actions were a response to poor treatment from Microsoft’s Security Response Center (MSRC), including ignored reports, withheld bounties, and account suspensions. Microsoft countered that coordinated disclosure was violated, putting users at risk. Among the disclosed bugs is CVE-2026-33825, which allows privilege escalation via local access to the SAM database. Despite patches issued during monthly updates, new exploits followed each fix, creating a cycle of vulnerability exposure and patch evasion.