Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

A handle keeps dropping MS zero-days

3 min read
18:20UTC

A researcher operating as Nightmare Eclipse has published a run of uncoordinated Microsoft zero-day disclosures since March. Microsoft says a fix for the latest is in development.

TechnologyDeveloping
Key takeaway

One handle has published five uncoordinated Microsoft zero-day disclosures since March; several specifics remain contested.

A researcher operating as Nightmare Eclipse has, since March, published a run of Microsoft zero-day disclosures with no Microsoft fix in place at the time of release, a series now circulating as Chaotic Eclipse 1. Each was a zero-day, meaning the researcher published the flaw before Microsoft had a patch ready. According to SecurityWeek, which has carried the primary reporting, the disclosures follow a dispute over Microsoft's bug-bounty handling 2. The researcher claims five exploits in the series: BlueHammer, RedSun, YellowKey, GreenPlasma, and RoguePlanet 3. The verifiable part is the run itself, five uncoordinated disclosures attributed to one handle against one vendor since March, and Microsoft has publicly restated its opposition to uncoordinated disclosure 4.

Two accounts of the latest entry conflict. This beat reported RoguePlanet in June's Patch Tuesday coverage as an actively-exploited Defender flaw at CVSS 9.6 . The Nightmare Eclipse research describes RoguePlanet differently, as CVE-2026-50656, a TOCTOU (time-of-check-to-time-of-use) race in Windows Defender rated CVSS 7.8, which the researcher says is unpatched with no confirmed exploitation in the wild 5. A TOCTOU race exploits the gap between when a programme checks a resource and when it uses it. Microsoft says a fix is in development and has set no date 6.

Those two accounts cannot both be right, and Lowdown is not resolving the CVSS number or the patch status here. Where the figures conflict between this briefing's earlier reporting and a single research source, they are flagged as claims rather than settled facts, and readers should treat them that way until Microsoft confirms a CVE, a severity, or a patch.

Deep Analysis

In plain English

Windows Defender is the antivirus and security software built into every Windows PC and server. It runs continuously in the background with high system privileges. A flaw in it can give an attacker the highest level of control over the machine, which makes Windows Defender a frequent target for researchers and attackers alike. A researcher called Nightmare Eclipse claims to have found such a flaw, called CVE-2026-50656, and published details publicly without giving Microsoft a chance to fix it first. This follows four previous similar disclosures since March 2026, all apparently stemming from a dispute over how much Microsoft paid the researcher for finding vulnerabilities. Microsoft says it is working on a fix but has not said when it will be ready. Until the patch arrives, any Windows user worldwide is potentially at risk from this unpatched flaw. The details are disputed: Microsoft's own June Patch Tuesday described what appears to be the same Windows Defender flaw but rated it as more severe and said it was already being exploited. Nightmare Eclipse's account rates the flaw as less severe and says it is not being exploited. Both cannot be fully correct.

What could happen next?
  • Risk

    Windows Defender is present on virtually every Windows installation; an unpatched SYSTEM-privilege flaw with public details and no vendor fix available creates an exposure window for every Windows endpoint and server globally until Microsoft ships the patch.

  • Precedent

    The Chaotic Eclipse series of five consecutive uncoordinated disclosures establishes a documented model for using serial zero-day publication as a leverage mechanism against vendors following bug-bounty disputes; if the model is not disrupted, it will attract imitators.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

SecurityWeek· 24 Jun 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.