Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/CyberSecurity News/GitLab Suspends Researcher After GitHub Ban for Windows Exploit
CyberSecurity News

GitLab Suspends Researcher After GitHub Ban for Windows Exploit

Key Takeaways Anonymous researcher Nightmare-Eclipse was suspended from GitLab on May 26, 2026, following a prior ban from GitHub on May 23, 2026. The suspensions occurred after the researcher...

Emy Elsamnoudy
Emy Elsamnoudy
May 27, 2026 3 Min Read
56 0

Key Takeaways

  • Anonymous researcher Nightmare-Eclipse was suspended from GitLab on May 26, 2026, following a prior ban from GitHub on May 23, 2026.
  • The suspensions occurred after the researcher publicly released multiple Windows Defender exploit tools, including BlueHammer (CVE-2026-33825), RedSun, and UnDefend.
  • These exploits, targeting Microsoft Windows Defender, enable privilege escalation and disruption of security features, with BlueHammer already patched and RedSun and UnDefend remaining unpatched as of May 2026.
  • Threat actors have been observed actively exploiting these tools in the wild, using them for privilege escalation after initial access.

GitLab Follows GitHub in Suspending Researcher Over Windows Exploit Disclosure

In a rapid sequence of events, security researcher Nightmare-Eclipse has faced suspension from two prominent code-hosting platforms within a single week. This action stems from their controversial public disclosure campaign targeting critical vulnerabilities in Microsoft Windows Defender, which has led to confirmed real-world exploitation.

Table Of Content

  • Key Takeaways
  • GitLab Follows GitHub in Suspending Researcher Over Windows Exploit Disclosure
  • Account Terminations on Major Platforms
  • The Genesis of the Disclosure Campaign
  • Active Exploitation Confirmed
  • Future Disclosures and Ethical Debate
  • What You Should Do

Account Terminations on Major Platforms

On May 26, 2026, GitLab officially suspended the account belonging to Nightmare-Eclipse. This move came just three days after Microsoft-owned GitHub terminated the researcher’s account around May 23, 2026. The GitLab page had served as a direct mirror for six Windows Defender exploit tools previously hosted on GitHub, effectively extending the reach of the researcher’s public disclosures even after the initial ban.

The Genesis of the Disclosure Campaign

The researcher’s campaign commenced on April 2, 2026, reportedly driven by deep dissatisfaction with the Microsoft Security Response Center (MSRC) and its perceived inadequate response to responsible vulnerability disclosures. Over several weeks, Nightmare-Eclipse released three high-profile proof-of-concept (PoC) tools specifically designed to target Windows Defender:

  • BlueHammer (CVE-2026-33825): This exploit leverages a Time-of-Check to Time-of-Use (TOCTOU) race condition, rated with a CVSS score of 7.8, within Defender’s threat remediation engine. It allows for privilege escalation to SYSTEM-level. Microsoft addressed this vulnerability in its April 2026 Patch Tuesday update, and it was subsequently added to CISA’s Known Exploited Vulnerabilities catalog on April 22.
  • RedSun: This tool exploits Defender’s cloud file rollback mechanism to execute arbitrary attacker-controlled binaries with SYSTEM privileges. As of May 2026, this vulnerability remains unpatched.
  • UnDefend: This exploit silently disrupts Defender’s signature update pipeline without triggering any health alerts, leading to a gradual degradation of endpoint protection over time. This flaw also remains unpatched.

Active Exploitation Confirmed

Huntress Labs confirmed active exploitation of all three tools as early as April 10, 2026. Threat actors were observed deploying these tools under deceptive filenames, such as “FunnyApp.exe.” Initial access for these campaigns was gained through compromised FortiGate VPN credentials, after which the Defender exploits were utilized for privilege escalation within the compromised environments.

Microsoft has indirectly criticized Nightmare-Eclipse, suggesting the researcher violated coordinated vulnerability disclosure best practices. While some of the reported flaws have been patched, others remain unaddressed.

Future Disclosures and Ethical Debate

Nightmare-Eclipse, who also maintains a Blogspot blog, has announced a significant disclosure event scheduled for July 14, 2026. The researcher has stated that this date will be impactful irrespective of any patches released prior to it.

This ongoing situation further fuels the persistent debate within the cybersecurity community concerning ethical disclosure timelines, the accountability of vendors and platforms, and the appropriate actions researchers should take when vendors become unresponsive to reported vulnerabilities.

What You Should Do

  • Apply Microsoft’s April 2026 Patch Tuesday updates immediately to address CVE-2026-33825 (BlueHammer).
  • Implement robust endpoint detection and response (EDR) solutions capable of detecting suspicious process execution and privilege escalation attempts, especially those involving Windows Defender components.
  • Monitor for the use of disguised filenames such as “FunnyApp.exe” or other unusual executables, particularly in conjunction with initial access through compromised VPN credentials.
  • Review and strengthen access controls for critical systems, ensuring that even if privilege escalation occurs, further lateral movement is restricted.
  • Stay vigilant for further advisories from Microsoft regarding RedSun and UnDefend, and be prepared to deploy patches as soon as they become available.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

CERT-In Urges Patching Critical Vulnerabilities in Multiple Systems

Next Post

Open RDP Ports Exploited for Initial Access to Business Networks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us