news.mlab.sh
Back to the feed
threat-intel

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Medium
Summary

Nightmare Eclipse, a researcher who previously exposed numerous Microsoft Defender vulnerabilities, has revealed his identity as Abdelhamid Naceri and released a new exploit, BigDiskBuster, that prevents Windows Defender updates. This follows a contentious departure from Microsoft, where he alleged unfair termination and a lack of explanation, leading to a lengthy and costly legal battle.

Nightmare Eclipse, a prolific researcher known for exposing vulnerabilities in Microsoft Defender, has finally revealed his true identity as Abdelhamid Naceri. For months, he has been publishing a rapid succession of proof-of-concept exploits targeting Windows and Microsoft Defender, often under the aliases Chaotic Eclipse and MNightmare. His latest offering, BigDiskBuster, is a proof-of-concept designed to block Windows Defender from completing its platform and signature updates.

According to the project’s GitHub page, BigDiskBuster is intended to work across all currently supported Windows versions, though the code is described as still requiring further refinement and testing. Nightmare Eclipse’s revelations come after a week of announcing his identity and detailing his difficult experience with Microsoft.

Prior to releasing BigDiskBuster, Nightmare Eclipse revealed that he is Abdelhamid Naceri, a researcher whose vulnerability discoveries had previously been highlighted in news reports. He described a sudden and unexplained termination from Microsoft, claiming the company offered him several financial settlements in an attempt to resolve the dispute, all of which he declined due to his desire for a clear explanation and assistance in remaining in Germany.

Naceri further stated that he challenged his dismissal in a German labor court, alleging Microsoft presented inconsistent arguments throughout the proceedings. The court ultimately upheld the termination, resulting in minimal compensation after a protracted and expensive legal battle. He claims this experience significantly impacted his mental health, leading to psychiatric treatment.

Notably, Naceri initially claimed that Microsoft had filed legal action against him, a claim made amidst Microsoft’s reaction to researchers disclosing zero-days. However, he has now admitted this was a fabrication. This incident highlights a complex and often adversarial relationship between security researchers and tech companies regarding vulnerability disclosure and zero-day exploitation.

Read the full article at SecurityWeek