The Microsoft bug leaker treating vulnerability disclosure as a countdown- 248
May 15, 2026
An anonymous researcher operating under the aliases Nightmare-Eclipse and Chaotic Eclipse has now released five Microsoft zero-days in a single year, framing each drop not as responsible disclosure but as retaliation for what they describe only as a betrayed agreement — and according to the security professionals tracking the campaign, they've followed through on every threat of more to come, including hints of a "dead man's switch" primed to release further remote-code-execution bugs regardless of what happens to them.
The two latest releases, YellowKey and GreenPlasma, arrived deliberately timed just after Microsoft's monthly Patch Tuesday update. YellowKey is the more alarming of the pair in practical terms: a BitLocker bypass requiring physical access to a target machine, delivered via a USB drive loaded with files that, if a specific key sequence completes correctly, grant unrestricted shell access to an otherwise encrypted device. Rik Ferguson, VP of security intelligence at Forescout, frames the stakes plainly — if the claim holds up, a stolen laptop stops being a hardware loss and becomes a breach notification, since BitLocker exists specifically as the last line of defense once a device physically leaves an organization's control. Gavin Knapp of Bridewell echoes that severity despite the physical-access requirement, calling YellowKey a serious problem for any organization relying on BitLocker, though he notes the exposure can be meaningfully reduced by pairing BitLocker with a PIN and locking the BIOS with a password. The researcher has also hinted, without offering verifiable evidence, that YellowKey may function as a backdoor Microsoft itself injected — a claim experts say is impossible to confirm from the information released so far.

GreenPlasma, by contrast, remains a work in progress for any attacker hoping to weaponize it. The researcher published only partial exploit code for the privilege-escalation flaw, which currently triggers a User Account Control consent prompt under default Windows configurations — meaning a silent, unprompted exploit chain doesn't yet exist, and turning the released code into a usable attack requires real additional engineering. That's a meaningful distinction from the pattern established by two of the researcher's earlier releases: RedSun, an admin privilege-escalation bug, and UnDefend, a denial-of-service flaw, both remain entirely unpatched, and proof-of-concept code for both was picked up and used in real-world attacks within a short window of release, according to threat-hunting firm Huntress. Only BlueHammer, the researcher's first disclosure, has been patched by Microsoft to date, in April.
The pattern across all five releases points to something closer to an escalating personal vendetta than a conventional bug-bounty grievance or state-sponsored disclosure campaign. Rumored to be a former Microsoft employee, the researcher's own account — posted under the Chaotic Eclipse alias — describes being left "homeless with nothing" after an unnamed party violated what they call an agreement, and frames every subsequent leak as a direct consequence of that betrayal rather than a considered security disclosure. Ferguson's assessment of where this goes next is unambiguous: prior releases have already attracted serious community attention and real code forks, the researcher's most recent post explicitly warns of another Patch Tuesday surprise, and the same post hints at a dead man's switch holding additional exploits in reserve — a threat Ferguson notes this particular researcher has followed through on every single time it's been made.