CyberSecurity SEE

Nightmare Eclipse Unveils Name and Story Behind MS Zero-Days

Nightmare Eclipse Unveils Name and Story Behind MS Zero-Days

Governance & Risk Management
,
Patch Management

Abdelhamid Naceri Shares His Story Amidst Tensions with Microsoft

Nightmare Eclipse Unveils Name and Story Behind MS Zero-Days
Image: Shutterstock

In a significant development within the cybersecurity community, Abdelhamid Naceri, a former Microsoft employee, recently disclosed his identity following a series of zero-day vulnerabilities that had caught the industry’s attention. Operating under various aliases—including Nightmare Eclipse, Chaotic Eclipse, and MSNightmare—Naceri took to social media platform X to share the turmoil that led to his ongoing dispute with Microsoft.

The conflict between Naceri and the tech giant appears to have ignited after Microsoft terminated his employment in 2024, leading to legal complications that persist to this day. Throughout this turbulent period, Naceri continued to publish Microsoft’s zero-day vulnerabilities, most recently revealing a flaw in their Defender software known as BigDiskBuster.

“Revealing my identity to the public is completely unrelated to Microsoft; I know they will never change their stance on me,” Naceri stated in an interview. “I’m just trying to find a new job,” he added, suggesting that his career had been fundamentally impacted by the fallout following his termination.

Previously, Naceri had adhered to the established vulnerability reporting protocols, having been noted in 2020 for disclosing a serious zero-day in Microsoft’s software and later identifying a vulnerability in Kaspersky’s antivirus solution, which was acknowledged by the firm in 2021. His reputable standing in the cybersecurity community led some peers to label him an “OG” (Original Gangster), highlighting his longstanding contributions to the field.

As Naceri recounted on his now-suspended social media account, he was informed of his dismissal by Tom Gallagher, Vice President of the Microsoft Security Response Center, who alleged that Naceri had shared confidential vulnerability information with unauthorized parties, which purportedly led to a security breach within the company.

In an email shared online, Gallagher mentioned, “This credible escalation has caused me to lose trust in you, and why we spoke earlier about a mutual separation.” Following this notification, Naceri was instructed to communicate his acceptance of the termination proposal to human resources within a week. However, discrepancies arose, as his termination letter dated March 2025 suggested that he would remain on a three-month gardening leave, during which he would not work but would still be compensated.

Moreover, Naceri revealed that despite his departure, Microsoft did not terminate his access to internal systems for an additional two months. He asserted that Gallagher informed him that the company intended to blacklist him, potentially impacting his prospects for future employment.

In 2026, Naceri took legal action against Microsoft in Germany, claiming unfair dismissal on the grounds that the company had failed to provide substantive evidence regarding the alleged security breach that led to his termination. Unfortunately for Naceri, a German labor court ruled in favor of Microsoft, leaving him to grapple with over $200,000 in legal fees.

The emotional toll of this prolonged conflict has been significant for Naceri, who has openly discussed the deterioration of his mental health. Having attended treatment at a psychiatric hospital, he shared his struggles with suicidal thoughts and substance use in blog posts earlier this year, illustrating the personal cost of his professional battles.

Since his termination, Naceri has leveraged his expertise by releasing multiple exploit codes targeting Microsoft Defender and vulnerabilities within Windows. His decision to independently publish these exploits occurred after Microsoft ceased communication with him, refused to compensate him for his findings, and deleted his account designated for reporting bugs.

To date, Naceri has disclosed twelve zero-day vulnerabilities, with names that include BlueHammer, RedSun, UnDefend, and MiniPlasma. His strategic approach appears to involve announcing these vulnerabilities on Microsoft’s Patch Tuesdays, effectively forcing the company to address these issues with limited response time.

The recent release of the BigDiskBuster flaw illustrates a vulnerability that could cripple the Defender software by filling up disk space on Windows endpoints, preventing security updates from being installed locally. This new revelation echoes earlier vulnerabilities such as UnDefend, further challenging Microsoft’s cybersecurity framework.

In May, Naceri’s public revelations prompted a fierce response from Microsoft, threatening a crackdown involving law enforcement against independent vulnerability disclosure. This statement led to widespread backlash from the cybersecurity community, requiring Microsoft to retract its threat.

While Naceri asserted that Microsoft had sued him, he later admitted to fabricating that claim, acknowledging, “MS never sued, I lied,” as he shared his narrative online. This admission adds another layer of complexity to an already intricate story of conflict and controversy involving one of the world’s leading tech companies.

If you or someone you know is experiencing a crisis, please contact the National Suicide Prevention Lifeline at 988 in the United States or visit SpeakingOfSuicide.com for additional support resources.

Source link

Exit mobile version