MS Nightmare

35 points · 5 comments · view on lemmy.world

5 Comments

TehBamski@lemmy.world · 8 pts · 69d (4 replies)

Could I get some context please?

01189998819991197253@infosec.pub · 22 pts · 69d (2 replies)

Sure!

https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge

TLDR from the link:

  • Nightmare-Eclipse (Chaotic Eclipse) is a malicious actor driven by a personal grievance against Microsoft.
  • The exploits published by this threat actor have been observed in threat activity linked to Russian-geolocated infrastructure.
  • Defenders should prioritize patching CVE-2026-33825, hardening BitLocker and layering network detection and identity controls that operate independently of the compromised endpoint.

...

  • Personal grievance. Claims Microsoft violated an agreement and "left me homeless with nothing." No evidence of financial motive or nation-state affiliation.
RustyNova@lemmy.world · 13 pts · 68d

Malicious actor

Not really. They reported the bug properly, Microslop hasn't upholded the contract, so they aren't going to uphold their end either.

TehBamski@lemmy.world · 6 pts · 69d

Thank you for filling me in.

plateee@piefed.social · 8 pts · 69d