INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Nightmare-Eclipse Exploit Drops RoguePlanet

| 2026-06-10 16:31 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The latest zero-day exploit, dubbed RoguePlanet, has been released by Nightmare-Eclipse, a researcher known for his relentless attacks on Microsoft. This time around, the vulnerability is a race condition that affects Windows Defender's signature update workflow, making it possible for attackers to gain access to compromised systems with complete control. The PoC was tested on multiple versions of Windows, including Windows 11 and Server, although Nightmare-Eclipse claims he won't redesign the exploit if Microsoft doesn't provide an explicit legal safe harbor. This latest incident highlights the ongoing cat-and-mouse game between researchers like Nightmare-Eclipse and security firms like MSRC, who are working to mitigate these types of threats.
Technical Mitigations AI-generated
• Microsoft should have properly addressed the reported vulnerabilities to prevent further exploits. • The public dispute between Nightmare-Eclipse and Microsoft has been ongoing, with both parties engaging in a cat-and-mouse game of disclosure and denial.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825 CVE-2026-45498CVE-2026-45498 CVE-2026-41091CVE-2026-41091
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎May 27
Nightmare-Eclipse exploited fully patched Windows.
organisation the Microsoft Security Response Center
organisation MSRC
‎2026/06/09
Nightmare-Eclipse used RoguePlanet to target fully patched Windows systems.
‎2026/06/10
Nightmare-Eclipse released a proof-of-concept exploit for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems.
infrastructure Windows
organisation ISO
organisation Nightmare-Eclipse
organisation GreenPlasma
organisation BitLocker
organisation the Windows Collaborative Translation Framework
organisation CTFMON
organisation CVE-2026-33825
organisation BlueHammer
infrastructure Ivanti
organisation Nightmare-Eclipse Drops
organisation Another Microsoft Exploit
organisation RoguePlanet
organisation Microsoft
organisation PoC
organisation Nightmare
organisation GitHub
organisation ShinyHunters
organisation YellowKey
organisation MiniPlasma
organisation RedSun
organisation Nightmare-Eclipse's
organisation Trend Micro's
organisation MSRC
organisation Digital Crimes Unit
organisation Spears
organisation Secure Future Initiative
organisation Coordinated Vulnerability Disclosure
organisation Microsoft Defender
organisation Microsoft’s Security Response Center
organisation SecurityAffairs
organisation Bug Bounty Research Triggers
organisation Microsoft Exchange
‎June 2026
The Nightmare-Eclipse exploit was successfully tested on fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates.
infrastructure Windows
organisation Canary
general_metric 11 Windows
general_metric 10 Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Ivanti
Affected Product