GitLab Suspends Researcher After GitHub Ban for Windows Exploit
Key Takeaways Anonymous researcher Nightmare-Eclipse was suspended from GitLab on May 26, 2026, following a prior ban from GitHub on May 23, 2026. The suspensions occurred after the researcher...
Key Takeaways
- Anonymous researcher Nightmare-Eclipse was suspended from GitLab on May 26, 2026, following a prior ban from GitHub on May 23, 2026.
- The suspensions occurred after the researcher publicly released multiple Windows Defender exploit tools, including BlueHammer (CVE-2026-33825), RedSun, and UnDefend.
- These exploits, targeting Microsoft Windows Defender, enable privilege escalation and disruption of security features, with BlueHammer already patched and RedSun and UnDefend remaining unpatched as of May 2026.
- Threat actors have been observed actively exploiting these tools in the wild, using them for privilege escalation after initial access.
GitLab Follows GitHub in Suspending Researcher Over Windows Exploit Disclosure
In a rapid sequence of events, security researcher Nightmare-Eclipse has faced suspension from two prominent code-hosting platforms within a single week. This action stems from their controversial public disclosure campaign targeting critical vulnerabilities in Microsoft Windows Defender, which has led to confirmed real-world exploitation.
Table Of Content
Account Terminations on Major Platforms
On May 26, 2026, GitLab officially suspended the account belonging to Nightmare-Eclipse. This move came just three days after Microsoft-owned GitHub terminated the researcher’s account around May 23, 2026. The GitLab page had served as a direct mirror for six Windows Defender exploit tools previously hosted on GitHub, effectively extending the reach of the researcher’s public disclosures even after the initial ban.
The Genesis of the Disclosure Campaign
The researcher’s campaign commenced on April 2, 2026, reportedly driven by deep dissatisfaction with the Microsoft Security Response Center (MSRC) and its perceived inadequate response to responsible vulnerability disclosures. Over several weeks, Nightmare-Eclipse released three high-profile proof-of-concept (PoC) tools specifically designed to target Windows Defender:
- BlueHammer (CVE-2026-33825): This exploit leverages a Time-of-Check to Time-of-Use (TOCTOU) race condition, rated with a CVSS score of 7.8, within Defender’s threat remediation engine. It allows for privilege escalation to SYSTEM-level. Microsoft addressed this vulnerability in its April 2026 Patch Tuesday update, and it was subsequently added to CISA’s Known Exploited Vulnerabilities catalog on April 22.
- RedSun: This tool exploits Defender’s cloud file rollback mechanism to execute arbitrary attacker-controlled binaries with SYSTEM privileges. As of May 2026, this vulnerability remains unpatched.
- UnDefend: This exploit silently disrupts Defender’s signature update pipeline without triggering any health alerts, leading to a gradual degradation of endpoint protection over time. This flaw also remains unpatched.
Active Exploitation Confirmed
Huntress Labs confirmed active exploitation of all three tools as early as April 10, 2026. Threat actors were observed deploying these tools under deceptive filenames, such as “FunnyApp.exe.” Initial access for these campaigns was gained through compromised FortiGate VPN credentials, after which the Defender exploits were utilized for privilege escalation within the compromised environments.
Microsoft has indirectly criticized Nightmare-Eclipse, suggesting the researcher violated coordinated vulnerability disclosure best practices. While some of the reported flaws have been patched, others remain unaddressed.
Future Disclosures and Ethical Debate
Nightmare-Eclipse, who also maintains a Blogspot blog, has announced a significant disclosure event scheduled for July 14, 2026. The researcher has stated that this date will be impactful irrespective of any patches released prior to it.
This ongoing situation further fuels the persistent debate within the cybersecurity community concerning ethical disclosure timelines, the accountability of vendors and platforms, and the appropriate actions researchers should take when vendors become unresponsive to reported vulnerabilities.
What You Should Do
- Apply Microsoft’s April 2026 Patch Tuesday updates immediately to address CVE-2026-33825 (BlueHammer).
- Implement robust endpoint detection and response (EDR) solutions capable of detecting suspicious process execution and privilege escalation attempts, especially those involving Windows Defender components.
- Monitor for the use of disguised filenames such as “FunnyApp.exe” or other unusual executables, particularly in conjunction with initial access through compromised VPN credentials.
- Review and strengthen access controls for critical systems, ensuring that even if privilege escalation occurs, further lateral movement is restricted.
- Stay vigilant for further advisories from Microsoft regarding RedSun and UnDefend, and be prepared to deploy patches as soon as they become available.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.