Nightmare-Eclipse (Chaotic Eclipse) is a malicious actor driven by a personal grievance against Microsoft.
The exploits published by this threat actor have been observed in threat activity linked to Russian-geolocated infrastructure.
Defenders should prioritize patching CVE-2026-33825, hardening BitLocker and layering network detection and identity controls that operate independently of the compromised endpoint.
...
Personal grievance. Claims Microsoft violated an agreement and "left me homeless with nothing." No evidence of financial motive or nation-state affiliation.
5 Comments
TehBamski@lemmy.world · 8 pts · 69d
Could I get some context please?
01189998819991197253@infosec.pub · 22 pts · 69d
Sure!
https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge
TLDR from the link:
RustyNova@lemmy.world · 13 pts · 68d
Not really. They reported the bug properly, Microslop hasn't upholded the contract, so they aren't going to uphold their end either.
TehBamski@lemmy.world · 6 pts · 69d
Thank you for filling me in.
plateee@piefed.social · 8 pts · 69d
I think it's this: https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-microsoft-exploit-rogueplanet