INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Nightmare-Eclipse Exploit Drops RoguePlanet
| 2026-06-10 16:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The latest zero-day exploit, dubbed RoguePlanet, has been released by Nightmare-Eclipse, a researcher known for his relentless attacks on Microsoft. This time around, the vulnerability is a race condition that affects Windows Defender's signature update workflow, making it possible for attackers to gain access to compromised systems with complete control. The PoC was tested on multiple versions of Windows, including Windows 11 and Server, although Nightmare-Eclipse claims he won't redesign the exploit if Microsoft doesn't provide an explicit legal safe harbor. This latest incident highlights the ongoing cat-and-mouse game between researchers like Nightmare-Eclipse and security firms like MSRC, who are working to mitigate these types of threats.
Technical Mitigations AI-generated
• Microsoft should have properly addressed the reported vulnerabilities to prevent further exploits.
• The public dispute between Nightmare-Eclipse and Microsoft has been ongoing, with both parties engaging in a cat-and-mouse game of disclosure and denial.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825
CVE-2026-45498CVE-2026-45498
CVE-2026-41091CVE-2026-41091
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
May 27
Nightmare-Eclipse exploited fully patched Windows.
Click on any entity below to view its context and source!
organisation
the Microsoft Security Response Center
In
a blog post
published on May 27, the Microsoft Security Response Center (MSRC) said the six vulnerabilities "were not responsibly disclosed," and condemned the researcher's actions, even going so far as to suggest it would pursue criminal charges against researchers like Nightmare-Eclipse that published zero-days.
organisation
MSRC
In
a blog post
published on May 27, the Microsoft Security Response Center (MSRC) said the six vulnerabilities "were not responsibly disclosed," and condemned the researcher's actions, even going so far as to suggest it would pursue criminal charges against researchers like Nightmare-Eclipse that published zero-days.
2026/06/09
Nightmare-Eclipse used RoguePlanet to target fully patched Windows systems.
2026/06/10
Nightmare-Eclipse released a proof-of-concept exploit for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems.
Click on any entity below to view its context and source!
infrastructure
Windows
It seems that there likely will be more releases of
zero-day exploits
for other issues with Windows Defender as well, as Nightmare-Eclipse — despite the admitted degradation of their "mental and physical health" in developing the latest PoC — shows no signs of stopping in their exploit vendetta against the company.
The latest zero-day is once again for Windows Defender, the Microsoft security service that was also impacted by other exploits released by Nightmare-Eclipse.
If successful, the exploit spawns a command shell running under SYSTEM-level privileges, which would give an attacker complete access to a compromised Windows machine.
At this time, the PoC does not work in Windows Server because "standard users cannot mount an ISO image."
However, all Windows Server versions are vulnerable if the exploit is redesigned to circumvent the issue, according to Nightmare-Eclipse, who said they won't redesign it themselves since "I'm done with this bug," according to the GitHub notes.
The exploit was for a zero-day tracked as
CVE-2026-33825
, a time-of-check to time-of-use (TOCTOU) vulnerability in Windows Defender's signature update workflow.
Chaotic Eclipse Unveils RoguePlanet Exploit Targeting Fully Patched Windows.
Chaotic Eclipse Unveils RoguePlanet Exploit Targeting Fully Patched Windows
The researcher Chaotic Eclipse released a PoC for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems.
The RoguePlanet exploit currently does not work on Windows Server because standard users cannot mount ISO images, although the researcher claims the underlying vulnerability still affects server installations and only requires a different exploitation method.
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
ISO
At this time, the PoC does not work in Windows Server because "standard users cannot mount an ISO image."
The RoguePlanet exploit currently does not work on Windows Server because standard users cannot mount ISO images, although the researcher claims the underlying vulnerability still affects server installations and only requires a different exploitation method.
organisation
Nightmare-Eclipse
However, all Windows Server versions are vulnerable if the exploit is redesigned to circumvent the issue, according to Nightmare-Eclipse, who said they won't redesign it themselves since "I'm done with this bug," according to the GitHub notes.
Security researcher
Chaotic Eclipse
, also known as Nightmare-Eclipse, has published a new proof-of-concept exploit for a RoguePlanet Microsoft Defender zero-day.
organisation
GreenPlasma
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
Nightmare-Eclipse then made good on this threat and disclosed five more PoC exploits for other Microsoft zero-day flaws: RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.
organisation
BitLocker
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
the Windows Collaborative Translation Framework
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
CTFMON
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
organisation
CVE-2026-33825
RoguePlanet is the latest vulnerability disclosed by researcher Chaotic Eclipse, following
BlueHammer
(CVE-2026-33825),
UnDefend
(CVE-2026-45498), and
RedSun
(CVE-2026-41091).
organisation
BlueHammer
RoguePlanet is the latest vulnerability disclosed by researcher Chaotic Eclipse, following
BlueHammer
(CVE-2026-33825),
UnDefend
(CVE-2026-45498), and
RedSun
(CVE-2026-41091).
It began with the release of the
"BlueHammer" exploit
in April from the researcher, who at first went by the name "Chaotic Eclipse."
infrastructure
Ivanti
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
"Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences," MSRC said in the post at the time.
organisation
Nightmare-Eclipse Drops
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet.
organisation
Another Microsoft Exploit
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet.
organisation
RoguePlanet
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet.
The researcher said he spent weeks working almost continuously to develop a working RoguePlanet exploit after Microsoft updates initially broke the prototype.
organisation
Microsoft
The researcher said he spent weeks working almost continuously to develop a working RoguePlanet exploit after Microsoft updates initially broke the prototype.
The zero-day "nightmare" apparently isn't over for Microsoft, as a disgruntled researcher who's been feuding with the company for the past three months has dropped yet another proof-of-concept (PoC) exploit for a purported zero-day flaw.
organisation
PoC
The zero-day "nightmare" apparently isn't over for Microsoft, as a disgruntled researcher who's been feuding with the company for the past three months has dropped yet another proof-of-concept (PoC) exploit for a purported zero-day flaw.
“As mentioned in the repo, it’s a race condition, I managed to stabilize it as much as I can but writing this PoC geniunely drained my soul.”
organisation
Nightmare
Some of those updates addressed previous several zero-day exploits published by Nightmare-Eclipse.
organisation
GitHub
The vulnerability this time is exploited by "a race condition, so it's a hit or miss," the researcher wrote in GitHub notes for the
RoguePlanet release
.
organisation
ShinyHunters
Related:
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Nightmare-Eclipse acknowledged that Microsoft tried to block their efforts to create the PoC and that they worked tirelessly to develop it for most of the month of May, an effort that "drained my soul," according to
the blog post
announcing RoguePlanet.
organisation
YellowKey
Nightmare-Eclipse then made good on this threat and disclosed five more PoC exploits for other Microsoft zero-day flaws: RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.
YellowKey could allow attackers to bypass BitLocker protections, while GreenPlasma enables privilege escalation.
organisation
MiniPlasma
Nightmare-Eclipse then made good on this threat and disclosed five more PoC exploits for other Microsoft zero-day flaws: RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma.
“The vulnerabilities known as
RedSun
,
UnDefend
,
BlueHammer
,
YellowKey
, GreenPlasma, and MiniPlasma were not responsibly disclosed.”
organisation
RedSun
That fix didn't stop
attackers from exploiting
BlueHammer, as well as targeting RedSun and UnDefend after Nightmare-Eclipse's disclosure of those exploits.
organisation
Nightmare-Eclipse's
That fix didn't stop
attackers from exploiting
BlueHammer, as well as targeting RedSun and UnDefend after Nightmare-Eclipse's disclosure of those exploits.
organisation
Trend Micro's
Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, says the situation with Nightmare-Eclipse will probably not end well.
organisation
MSRC
The researcher criticized Microsoft for revoking access to their MSRC account, rejecting reports, and failing to provide compensation.
organisation
Digital Crimes Unit
"Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world.
organisation
Spears
"
"It also means ending what researchers describe here: a flaw patched in silence, and then the finder blamed in public," Spears observes.
organisation
Secure Future Initiative
In response, Microsoft made vulnerability disclosure and transparency a core pillar of the company's
Secure Future Initiative
(SFI) in 2023 and later
touted improvements
in those areas.
organisation
Coordinated Vulnerability Disclosure
Microsoft’s post is essentially a public defense of Coordinated Vulnerability Disclosure, the standard practice where a researcher notifies a vendor privately, gives them time to fix the issue, and then goes public.
organisation
Microsoft Defender
The researcher also alleged that Microsoft Defender remains vulnerable and claimed to have discovered additional memory corruption flaws and other security issues affecting multiple components.
organisation
Microsoft’s Security Response Center
At the end of May, Microsoft’s Security Response Center
called
the zero-day dumps irresponsible.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Chaotic Eclipse)
organisation
Bug Bounty Research Triggers
Related:
Bug Bounty Research Triggers ServiceNow Security Alert
Nightmare-Eclipse acknowledged that Microsoft tried to block their efforts to create the PoC and that they worked tirelessly to develop it for most of the month of May, an effort that "drained my soul," according to
the blog post
announcing RoguePlanet.
organisation
Microsoft Exchange
Related:
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
"Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences," MSRC said in the post at the time.
June 2026
The Nightmare-Eclipse exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates.
Click on any entity below to view its context and source!
infrastructure
Windows
The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse.
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
organisation
Canary
The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse.
general_metric
11 Windows
The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse.
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
general_metric
10 Windows
The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse.
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
It seems that there likely will be more releases of
zero-day exploits
for other issues with Windows Defender as well, as Nightmare-Eclipse — despite the admitted degradation of their "mental and physical health" in developing the latest PoC — sho…
The latest zero-day is once again for Windows Defender, the Microsoft security service that was also impacted by other exploits released by Nightmare-Eclipse.
If successful, the exploit spawns a command shell running under SYSTEM-level privileges, which would give an attacker complete access to a compromised Windows machine.
At this time, the PoC does not work in Windows Server because "standard users cannot mount an ISO image."
However, all Windows Server versions are vulnerable if the exploit is redesigned to circumvent the issue, according to Nightmare-Eclipse, who said they won't redesign it themselves since "I'm done with this bug," according to the GitHub notes.
The PoC was tested on Windows 11, both the official channel and Canary releases, as well as Windows 10 with the June 2026 Patch Tuesday update installed, according to Nightmare-Eclipse.
The exploit was for a zero-day tracked as
CVE-2026-33825
, a time-of-check to time-of-use (TOCTOU) vulnerability in Windows Defender's signature update workflow.
Chaotic Eclipse Unveils RoguePlanet Exploit Targeting Fully Patched Windows.
Chaotic Eclipse Unveils RoguePlanet Exploit Targeting Fully Patched Windows
The researcher Chaotic Eclipse released a PoC for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems.
The exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the
June 2026 Patch Tuesday
updates, showing that patched systems may still be vulnerable.
The RoguePlanet exploit currently does not work on Windows Server because standard users cannot mount ISO images, although the researcher claims the underlying vulnerability still affects server installations and only requires a different exploitat…
In May, the researcher disclosed two other
Windows zero-day vulnerabilities
named
YellowKey
and
GreenPlasma
.
The flaws affect BitLocker and the Windows Collaborative Translation Framework (CTFMON).
Metrics
infrastructure
Ivanti
Affected Product
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
"Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences," MSRC…
Intelligence Sources
Security Affairs
2026-06-10
Dark Reading
2026-06-10
Dark Reading
2026-06-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
33x
organisation
Identified Entity
ISO
entity
4x
timeline
Temporal Reference
2026/06/09
date
3x
industry
Targeted Sector
Legal
sector
3x
vulnerability
Exploited CVE
CVE-2026-33825
cve
2x
infrastructure
Affected Product
Windows
software
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
6 METRICS
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
general metric
Hours
24
hours
general metric
Claude Fable
5
claude fable
target region
Target Country
United States
country
tactic
Cyber Operation Type
Privilege Escalation
tactic
general metric
%
100
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.