The Disgruntled Researcher and the Dead Man's Switch: Nightmare-Eclipse's Zero-Day Campaign- 184
June 5, 2026
Five Windows zero-days in a single year, released by a single anonymous researcher, timed to maximally embarrass Microsoft and benefit attackers. Nightmare-Eclipse has made the deliberate malicious disclosure of unpatched Windows vulnerabilities into a sustained retaliatory campaign, with each release accompanied by enough technical detail to enable exploitation and a running threat of more to come. The researcher's self-stated motivation is personal: a claimed betrayal, a violated agreement, being left "homeless with nothing." The security community's problem is that the motivation is irrelevant to the consequences.
The two most recent disclosures — YellowKey and GreenPlasma, released in May 2026 immediately following Microsoft's monthly Patch Tuesday — illustrate both the campaign's escalating ambition and the specific threat it poses. YellowKey is a BitLocker bypass delivered via a USB drive, requiring physical access to a Windows machine but providing, if executed correctly, unrestricted shell access to a BitLocker-protected device. The implications are not theoretical: BitLocker exists precisely as the last line of defense for stolen hardware. A bypass means that a stolen laptop is no longer a hardware problem — it becomes a data breach notification event. Rik Ferguson, VP of security intelligence at Forescout, stated the consequence plainly: if the claim holds up, "a stolen laptop stops being a hardware problem and becomes a breach notification." Mitigation exists and is specific: implementing a BitLocker PIN alongside a BIOS password lock prevents the attack. Organizations that have not taken that step are exposed.
GreenPlasma is a privilege escalation flaw granting SYSTEM access, for which Nightmare-Eclipse released partial rather than complete exploit code — the weaponization work remains for attackers to complete, a step that security professionals describe as nontrivial in GreenPlasma's current form. No mitigation currently exists. When Microsoft addresses it, patching will be the only remediation. Until then, organizations should treat the partial code as a signal that exploitation capability is actively developing in the criminal community.
The three earlier disclosures from this campaign set the trajectory. BlueHammer (CVE-2026-32201, now patched) was released in April alongside RedSun (admin privilege escalation) and UnDefend (a Windows Defender denial-of-service flaw). Both RedSun and UnDefend remain unpatched. Huntress has confirmed that proof-of-concept code for both was quickly adopted into real-world attacks — the gap between academic vulnerability disclosure and active criminal exploitation measured in days, not weeks. The researcher's claimed dead man's switch — more vulnerabilities ready to release, with a further promise of remote code execution disclosures — makes this not a discrete incident but an ongoing condition. Each Patch Tuesday is now accompanied by the possibility of a coordinated counter-release from a researcher who has followed through on every prior threat.
The structural problem the Nightmare-Eclipse campaign exposes is not unique to Microsoft or to this researcher. Adversarial vulnerability disclosure — the deliberate publication of unpatched flaws with the intent to cause maximum harm — is a threat category that sits outside the established norms of coordinated disclosure, outside bug bounty programs, and outside the remediation timelines that the patch cycle assumes. The criminal ecosystem does not wait for CVE registration, vendor acknowledgment, or patch availability. It forks the proof-of-concept code and deploys.
