Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Former Microsoft employee Abdelhamid Naceri reveals himself as Nightmare Eclipse, releases new Windows Defender PoC
Summary
Abdelhamid Naceri, a former Microsoft Germany employee, has publicly revealed himself as the researcher known as Nightmare Eclipse (also Chaotic Eclipse) who has been releasing Windows and Microsoft Defender proof-of-concept exploits. Naceri released a new PoC exploit called BigDiskBuster that prevents Windows Defender from completing platform and signature updates across all supported Windows versions. He attributed his exploit releases to emotional and financial hardship following his disputed termination from Microsoft and unsuccessful German labor court challenge.
Full text
The researcher known online as Nightmare Eclipse, who has spent months publishing a rapid string of Windows and Microsoft Defender proof-of-concept exploits, has revealed his identity and released another Defender exploit. Posting under the name Abdelhamid Naceri, the researcher announced a new PoC exploit called BigDiskBuster over the weekend. According to the project’s GitHub page, BigDiskBuster is a proof of concept “similar to UnDefend” that prevents Windows Defender from completing its platform and signature updates. He describes it as working on all currently supported Windows versions, while cautioning that the code is still buggy and needs further work. SecurityWeek has reached out to Microsoft for comment on the BigDiskBuster exploit and will update this article if the company responds. Nightmare Eclipse is Abdelhamid Naceri About a week before releasing BigDiskBuster, Nightmare Eclipse, also known online as Chaotic Eclipse and MSNightmare, revealed that he is Abdelhamid Naceri, a researcher whose vulnerability discoveries were featured in the news half a decade ago. Advertisement. Scroll to continue reading. After working with Microsoft in the UK and Germany, Naceri shared a public account of his departure from the company from a now-deleted X account. According to Naceri’s account, Microsoft terminated his employment abruptly and without providing a clear justification. He alleged that the company offered him several financial settlement options to resolve the dispute, all of which he claims to have rejected because he sought a formal explanation and assistance remaining in Germany. Naceri also claimed that he challenged his dismissal in a German labor court, alleging that Microsoft presented shifting arguments throughout the proceedings. By his own account, the court ultimately upheld the termination, leaving him with virtually no compensation after a prolonged and costly legal effort. Naceri said the emotional and financial fallout from the dispute severely impacted his mental health, claiming he was receiving treatment in a psychiatric hospital. The researcher admitted that previous claims that Microsoft filed legal action against him — a claim made while Microsoft faced backlash over threats of legal action against researchers who disclose zero-days — were fabricated. Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Dragos Completes NetRise and runZero Acquisitions Following Accenture DealRust Team Members and Popular Crate Owners Targeted via Video CallsColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsGoogle Confirms Gemini AI Breached Three FirmsAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsCheck Point, Kaspersky, Tanium Patch Product Vulnerabilities Latest News Only 13% of OT Network Segments Are Fully Isolated: AnalysisRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeUS Proposes AI Incident Alert System in Talks With China, Bessent SaysGoogle Hit With $463 Million Fine for EU Location Data Rule BreachFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — BigDiskBuster
- malware — UnDefend