Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Nightmare Eclipse, a security researcher, has released a new zero-day exploit, ‘HardBreacher,’ targeting a Kaspersky Endpoint Security product, allowing attackers to gain significant control over the system. This exploit, along with others, has been actively used by malicious actors, and Kaspersky has released a patch to address the vulnerability.
A security researcher known as Nightmare Eclipse has been releasing a series of zero-day exploits recently, primarily focusing on Windows and Microsoft Defender vulnerabilities. The researcher's actions stem from frustration with Microsoft’s handling of vulnerability reports. Several of these exploits have progressed beyond the proof-of-concept stage and have been actively exploited in the wild by malicious actors.
Over the weekend, Nightmare Eclipse released ‘HardBreacher,’ a zero-day exploit targeting a privilege escalation vulnerability within Kaspersky Endpoint Security. The researcher described the exploit as ‘basically duct taped’ and noted that it causes the Kaspersky product to malfunction, allowing attackers to access files it shouldn’t and potentially destabilize the entire operating system.
Kaspersky acknowledged the issue and confirmed that a fix has been implemented and delivered through automatic updates, or users can manually trigger a database update. Other recently released exploits by Nightmare Eclipse include ‘ShieldBreak,’ which enables a shell with system privileges, and ‘LegacyHive,’ which facilitates privilege escalation.
This incident highlights the ongoing threat posed by independent researchers releasing vulnerabilities and the importance of timely patching and security updates.