GitHub bans Nightmare‑Eclipse for Windows exploits

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- GitHub banned the account of security researcher Nightmare‑Eclipse (aka Chaotic Eclipse) after they posted Windows zero‑day exploits.
- Nightmare‑Eclipse says the ban is vindictive, claims Microsoft refused communication and unpaid bug bounties, and threatens a "reckoning" on July 14.
- Microsoft has not commented on the dispute, leaving it unclear whether the ban stems from non‑compliance with disclosure rules or other reasons.
- MSRC offers bounties up to $30,000–$100,000 per endpoint zero‑day and $250,000 for Hyper‑V exploits, but the researcher says they received no payment.
- BlueHammer and other exploits (RedSun, UnDefend, GreenPlasma, MiniPlasma, YellowKey) were published by the researcher, granting SYSTEM access or bypassing BitLocker, with some confirmed to be actively exploited.
- William Dormann of Tharros suggested Microsoft may have closed the case after the researcher refused to submit a video of the exploit, a new MSRC requirement.
- AI‑powered security research is making the traditional 90‑day disclosure‑to‑patch window obsolete, prompting calls for policy adjustments.
Why it matters: The ban removes the researcher’s GitHub platform but does not erase the published zero‑day code, leaving Microsoft’s Windows products exposed while the researcher shifts to GitLab and threatens further releases, exposing gaps in Microsoft’s bounty‑payment and disclosure policies and the broader security community loses confidence in the vulnerability‑handling process.
Ask SkimNews


