Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

A handle keeps dropping MS zero-days

3 min read
12:09UTC

A researcher operating as Nightmare Eclipse has published a run of uncoordinated Microsoft zero-day disclosures since March. Microsoft says a fix for the latest is in development.

TechnologyDeveloping
Key takeaway

One handle has published five uncoordinated Microsoft zero-day disclosures since March; several specifics remain contested.

A researcher operating as Nightmare Eclipse has, since March, published a run of Microsoft zero-day disclosures with no Microsoft fix in place at the time of release, a series now circulating as Chaotic Eclipse 1. Each was a zero-day, meaning the researcher published the flaw before Microsoft had a patch ready. According to SecurityWeek, which has carried the primary reporting, the disclosures follow a dispute over Microsoft's bug-bounty handling 2. The researcher claims five exploits in the series: BlueHammer, RedSun, YellowKey, GreenPlasma, and RoguePlanet 3. The verifiable part is the run itself, five uncoordinated disclosures attributed to one handle against one vendor since March, and Microsoft has publicly restated its opposition to uncoordinated disclosure 4.

Two accounts of the latest entry conflict. This beat reported RoguePlanet in June's Patch Tuesday coverage as an actively-exploited Defender flaw at CVSS 9.6 . The Nightmare Eclipse research describes RoguePlanet differently, as CVE-2026-50656, a TOCTOU (time-of-check-to-time-of-use) race in Windows Defender rated CVSS 7.8, which the researcher says is unpatched with no confirmed exploitation in the wild 5. A TOCTOU race exploits the gap between when a programme checks a resource and when it uses it. Microsoft says a fix is in development and has set no date 6.

Those two accounts cannot both be right, and Lowdown is not resolving the CVSS number or the patch status here. Where the figures conflict between this briefing's earlier reporting and a single research source, they are flagged as claims rather than settled facts, and readers should treat them that way until Microsoft confirms a CVE, a severity, or a patch.

Deep Analysis

In plain English

Windows Defender is the antivirus and security software built into every Windows PC and server. It runs continuously in the background with high system privileges. A flaw in it can give an attacker the highest level of control over the machine, which makes Windows Defender a frequent target for researchers and attackers alike. A researcher called Nightmare Eclipse claims to have found such a flaw, called CVE-2026-50656, and published details publicly without giving Microsoft a chance to fix it first. This follows four previous similar disclosures since March 2026, all apparently stemming from a dispute over how much Microsoft paid the researcher for finding vulnerabilities. Microsoft says it is working on a fix but has not said when it will be ready. Until the patch arrives, any Windows user worldwide is potentially at risk from this unpatched flaw. The details are disputed: Microsoft's own June Patch Tuesday described what appears to be the same Windows Defender flaw but rated it as more severe and said it was already being exploited. Nightmare Eclipse's account rates the flaw as less severe and says it is not being exploited. Both cannot be fully correct.

What could happen next?
  • Risk

    Windows Defender is present on virtually every Windows installation; an unpatched SYSTEM-privilege flaw with public details and no vendor fix available creates an exposure window for every Windows endpoint and server globally until Microsoft ships the patch.

  • Precedent

    The Chaotic Eclipse series of five consecutive uncoordinated disclosures establishes a documented model for using serial zero-day publication as a leverage mechanism against vendors following bug-bounty disputes; if the model is not disrupted, it will attract imitators.

First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

SecurityWeek· 24 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.