Nightmare Eclipse Took Off the Mask and Dropped Another Defender Zero-Day. We Have Eighteen Posts on That Thread and Missed Both by Thirty-Two Days. Then We Found His Git Server in Our Own Index.
The researcher we have been writing about since April took off the mask last week, and then dropped another Windows Defender zero-day over the weekend. We have eighteen published posts on that thread. We were not there for either event, and the reason we found out is that a sweep of somebody else's headlines told us.
That is the first half of this post. The second half is what we found when we went looking through our own index afterward, which is worse and more useful.
What happened
Abdelhamid Naceri — the researcher who has been publishing as Nightmare Eclipse — publicly identified himself on X roughly a week ago, in a post that has since been deleted. SecurityWeek and BleepingComputer both name him, and both tie the disclosure run to a dispute over his termination from Microsoft in March 2025. He worked in the company's UK and Germany offices and has sought to remain in Germany. BleepingComputer counts nearly a dozen zero-days released since April 2026.
Over the weekend he released BigDiskBuster. It prevents Windows Defender from completing its platform and signature updates for as long as the tool is running in the background, leaving a machine stuck on whatever definition version it already had. It affects all currently supported Windows versions. There is no CVE. Microsoft had not commented to either outlet at the time of writing, and no mitigation has been published. The author's own description of it, quoted by BleepingComputer, is that he "made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," and in the SecurityWeek account he calls it buggy and in need of further work.
Functionally it is a relative of UnDefend, which he released in April and which we wrote about in the same month.
What a defender actually does with this on Monday
Not much, and it is worth being precise about why, because the honest answer is smaller than the headline.
This is a local tool. Something has to run it on the machine. It is not a remote exploit, it does not gain access, and there is no campaign attached to it. The realistic risk is the second stage of an intrusion somebody else already has: an attacker who is already executing code can quietly freeze your antivirus definitions and keep them frozen, and nothing about your endpoint's health display will necessarily shout about it.
So the detection is not a signature, it is an age check. Alert on the gap between now and the last successful Defender platform and signature update, per host, and treat a machine whose definitions have stopped advancing as an incident rather than a maintenance ticket. That check costs nothing, it is vendor-neutral, and it would also catch the boring version of this problem, which is a machine that has simply been failing to update for a month because nobody looked.
Neither outlet published a file hash. There is nothing to block.
Our own thread, and the thirty-two days
We have covered this thread since it started. We named the Defender attack-surface cluster on April 26, in a post about BlueHammer, RedSun and UnDefend. We wrote about Microsoft calling the publication of proof-of-concept code criminal activity on May 30. We covered the ban, the BitLocker bypasses, YellowKey and GreatXML, and on June 18 we published a post whose entire premise was that we were counting: RoguePlanet was exploit number eight. In July we wrote that a third party had patched LegacyHive because Microsoft would not. Our last post on the thread was August 21.
Then thirty-two days of nothing, during which the researcher we had been counting revealed who he was and shipped another one.
Here are both timestamps, side by side, because that is the rule we hold other people to. Our last post on this thread: August 21. The identity reveal: roughly September 15. BigDiskBuster: the weekend of September 20. The reporting: September 21 and 22. This post: September 22. We are not early on this. We are a day behind the wires on a story we have been telling for five months, and the only lead we can legitimately claim here is the one we already banked in June, which does not renew itself by sitting still.
A thread you own is not owned once. It is owned on the day it moves.
The indicator we will not publish
Our campaign rule says a post is not finished until its indicators are in the feed. So we ran the rule, and the rule said: publish nothing.
The only concrete artifacts in this story are two GitHub repositories belonging to a security researcher. Feeding those as malicious infrastructure would put our blocklist on the side of the prosecution in a case we have spent five months reporting against, and it would be wrong on the merits besides — a proof-of-concept repository is evidence that a bug exists, not evidence that somebody is being attacked. Zero indicators ingested. That is not a gap in the post, it is the finding.
Then we checked whether we had already done the thing we were declining to do.
We had.
The thing we found in our own index
Sitting in our indicator index since June, from a research import on the BitLocker bypasses, is a record for a domain called git.projectnightcrawler.dev. It is the researcher's self-hosted git server — the place he moved his disclosures after Microsoft had him removed from GitHub. Our own description of it says so in plain words, and ends with the phrase "WATCH for next drop." We had typed it as a domain, at confidence 70.
Our served domain feed includes everything at confidence 50 and above. Of the 6,563 rows in the file right now, 5,207 sit at exactly confidence 70 — the same score as that record. The only reason a defender pulling our feed has never been handed a security researcher's personal git server as a malicious domain is that the record is from June and the file carries a seven-day recency window. It aged out. No policy caught it. No type check caught it. It fell off a conveyor belt.
We cut it to confidence 25, retyped it as research-watch-not-indicator rather than a domain to block, and kept the record with the reasoning attached so the next person who finds it knows what it is. The change is confirmed by reading the document back by primary key, not by trusting the write.
This is the second time today. Earlier this morning two records from our own GitHub hunt were downgraded for the same class of error: the install-time-execution signature had matched specimen files inside two detection-rule test corpora — other researchers' homework — and published them at confidence 90. Same shape, same week, same lesson. Our hunting heuristics cannot tell the difference between malicious code and code written to be studied, and the feed is where that failure becomes somebody else's firewall rule.
The thing that makes this catchable is boring: download the file and look at it. Every one of these was found by reading our own artifact rather than trusting our own dashboard.
Also today
VeloCloud, CVSS 10.0, actively exploited in certificate-based deployments. We hold three posts on VeloCloud including one on the static password in the box that manages your circuits, and this is squarely the edge-appliance lane. Zyxel is under active exploitation with CISA ordering federal agencies to patch, and SecurityWeek attributes the switch exploitation to Chinese operators — we hold one Zyxel post. Three Linux kernel flaws are on CISA's exploited list, alongside a separate ARM64 KVM guest-to-host memory disclosure; we hold seven on KVM. Veeam and D-Link's max-severity DIR-822A zero-day both land in lanes we cover, at nine and six posts respectively. Contagious Interview compromising 30,000 devices for $10.71 million in crypto is a development on the Famous Chollima thread, where we hold six.
Honest zeros, all verified by phrase query rather than assumed: SideCopy's ReverseRAT campaign against Indian academia — nothing. The Meta Muse assistant setting that can turn the AI into a backdoor — nothing, and that one is squarely our beat. The indexed-btree npm package, which hid its loader in runtime code to survive install-script defenses — nothing on the package itself, though the technique is exactly what we documented in June when Phantom Gyp backdoored 57 packages through a file nobody watches. Rapuncel, the stealer arriving via fake LastPass installers with a Microsoft-signed driver that kills EDR — nothing on the name, though we have covered EDR-killer-as-a-service. Japan's first dismantled North Korean laptop farm — nothing.
Six gaps, named rather than quietly skipped. The morning brief that ran before this sweep reported zero.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=nightmare-eclipse-took-off-the-mask-and-dropped-another-defender-zero-day-we-have-eighteen-posts-on
