Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

A handle keeps dropping MS zero-days

3 min read
16:08UTC

A researcher operating as Nightmare Eclipse has published a run of uncoordinated Microsoft zero-day disclosures since March. Microsoft says a fix for the latest is in development.

TechnologyDeveloping
Key takeaway

One handle has published five uncoordinated Microsoft zero-day disclosures since March; several specifics remain contested.

A researcher operating as Nightmare Eclipse has, since March, published a run of Microsoft zero-day disclosures with no Microsoft fix in place at the time of release, a series now circulating as Chaotic Eclipse 1. Each was a zero-day, meaning the researcher published the flaw before Microsoft had a patch ready. According to SecurityWeek, which has carried the primary reporting, the disclosures follow a dispute over Microsoft's bug-bounty handling 2. The researcher claims five exploits in the series: BlueHammer, RedSun, YellowKey, GreenPlasma, and RoguePlanet 3. The verifiable part is the run itself, five uncoordinated disclosures attributed to one handle against one vendor since March, and Microsoft has publicly restated its opposition to uncoordinated disclosure 4.

Two accounts of the latest entry conflict. This beat reported RoguePlanet in June's Patch Tuesday coverage as an actively-exploited Defender flaw at CVSS 9.6 . The Nightmare Eclipse research describes RoguePlanet differently, as CVE-2026-50656, a TOCTOU (time-of-check-to-time-of-use) race in Windows Defender rated CVSS 7.8, which the researcher says is unpatched with no confirmed exploitation in the wild 5. A TOCTOU race exploits the gap between when a programme checks a resource and when it uses it. Microsoft says a fix is in development and has set no date 6.

Those two accounts cannot both be right, and Lowdown is not resolving the CVSS number or the patch status here. Where the figures conflict between this briefing's earlier reporting and a single research source, they are flagged as claims rather than settled facts, and readers should treat them that way until Microsoft confirms a CVE, a severity, or a patch.

Deep Analysis

In plain English

Windows Defender is the antivirus and security software built into every Windows PC and server. It runs continuously in the background with high system privileges. A flaw in it can give an attacker the highest level of control over the machine, which makes Windows Defender a frequent target for researchers and attackers alike. A researcher called Nightmare Eclipse claims to have found such a flaw, called CVE-2026-50656, and published details publicly without giving Microsoft a chance to fix it first. This follows four previous similar disclosures since March 2026, all apparently stemming from a dispute over how much Microsoft paid the researcher for finding vulnerabilities. Microsoft says it is working on a fix but has not said when it will be ready. Until the patch arrives, any Windows user worldwide is potentially at risk from this unpatched flaw. The details are disputed: Microsoft's own June Patch Tuesday described what appears to be the same Windows Defender flaw but rated it as more severe and said it was already being exploited. Nightmare Eclipse's account rates the flaw as less severe and says it is not being exploited. Both cannot be fully correct.

What could happen next?
  • Risk

    Windows Defender is present on virtually every Windows installation; an unpatched SYSTEM-privilege flaw with public details and no vendor fix available creates an exposure window for every Windows endpoint and server globally until Microsoft ships the patch.

  • Precedent

    The Chaotic Eclipse series of five consecutive uncoordinated disclosures establishes a documented model for using serial zero-day publication as a leverage mechanism against vendors following bug-bounty disputes; if the model is not disrupted, it will attract imitators.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

SecurityWeek· 24 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.