A Researcher Named ‘Nightmare Eclipse’ Keeps Leaking Microsoft Defender Zero-Days Because the Bug Bounty Program Made It Personal — RoguePlanet Gives SYSTEM Access and the Patch Timeline Is ‘We’re Working on It’

🤚 The Open-Palm Disclosure

A security researcher operating under the handle “Nightmare Eclipse” has disclosed a new zero-day vulnerability in Microsoft Defender’s Malware Protection Engine that allows attackers to spawn command prompts with SYSTEM-level privileges on fully patched Windows 10 and Windows 11 devices. The vulnerability, assigned CVE-2026-50656 on June 17, has been named RoguePlanet, and a proof-of-concept exploit is publicly available on the researcher’s self-hosted Git repository.

The exploit is a race condition within Defender itself. In the researcher’s own words: “The exploit is a race condition, so it’s a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others.” The vulnerability works regardless of whether real-time protection is enabled, which is a detail that should concern approximately everyone who has ever used a Windows computer, which is approximately everyone.

Microsoft has confirmed it is “actively working on a security update” but has not provided a timeline. The company’s official statement: “We are working to provide a high quality security update that addresses this vulnerability.” High quality. Not fast. High quality.

👐 The Two-Handed Grudge Match

If the name Nightmare Eclipse sounds familiar, it should. This researcher has a documented history of leaking Windows zero-days due to ongoing disputes with Microsoft over its bug bounty practices and vulnerability disclosure processes. Previous disclosures from the same researcher include BlueHammer, RedSun, GreenPlasma, and several others — a color-coded portfolio of privilege escalation vulnerabilities that reads like a paint swatch catalog for system compromise.

As we covered in May, a researcher published a Windows exploit on GitHub as what amounted to a resignation letter from the bug bounty program. Nightmare Eclipse has taken that energy and turned it into a serialized publication schedule. Each disclosure follows the same pattern: find vulnerability, report to Microsoft, receive unsatisfactory response, publish proof-of-concept, wait for Microsoft to say “we’re working on it,” find another vulnerability.

Some of these earlier zero-days — YellowKey, GreenPlasma, and MiniPlasma — were eventually patched in Microsoft’s June Patch Tuesday. But RoguePlanet arrived after that cycle, meaning the next scheduled fix is weeks away, and the exploit is live now.

This is not a rogue nation-state. This is not a ransomware gang. This is a single researcher who feels undercompensated and has decided that the most efficient way to communicate this is to keep publishing elevation-of-privilege vulnerabilities in the software that 1.4 billion people depend on to stop malware.

🌿 The Gentle Awakening

The bug bounty model is built on a premise: that paying researchers a fraction of what a vulnerability is worth on the black market will, through the magic of civic duty and a modest check, keep them on the right side of the disclosure fence. For most researchers, this works. For Nightmare Eclipse, the fence has been removed, replaced with a Git repository and a grudge.

There’s a particular irony in a Defender zero-day. This is not a vulnerability in some forgotten legacy service. This is the antivirus engine — the software that runs with the highest privileges on your system specifically so it can protect you from things that want those same privileges. When the guard is the vulnerability, the threat model doesn’t just break. It inverts.

And because it’s a race condition, your exposure is partially determined by your CPU scheduler’s mood. Some machines are exploited 100% of the time. Others resist. Your security posture now depends on whether your processor happens to context-switch at the wrong nanosecond, which is the computational equivalent of hoping the mugger trips on the curb.

👑 The Gold-Leaf Reckoning

Microsoft’s vulnerability ecosystem has entered a new phase where one motivated individual with a color-naming convention can generate more unpatched zero-days than most nation-state programs. BlueHammer. RedSun. GreenPlasma. YellowKey. MiniPlasma. RoguePlanet. The researcher has more branded vulnerabilities than most cybersecurity companies have branded products.

The fix for RoguePlanet will arrive when it arrives. In the meantime, every Windows device running Defender — which is to say, every Windows device — carries an elevation-of-privilege vulnerability in its primary security tool. The proof-of-concept is public. The mitigation guidance is “wait.”

What makes this story genuinely uncomfortable is that Nightmare Eclipse is not wrong about the structural incentive problem. Bug bounties pay researchers thousands of dollars for vulnerabilities that, in the wrong hands, are worth millions. The program works because most researchers have ethics. When one doesn’t — or more precisely, when one has different ethics — the entire model reveals itself as a gentleman’s agreement enforced by nothing but goodwill.

RoguePlanet is not the last. If the pattern holds, the next color-coded zero-day is already found, already reported, and already waiting for a bug bounty response that will, apparently, be unsatisfactory.

“The software designed to protect your computer from privilege escalation now has a privilege escalation vulnerability, and the person who keeps finding them is named ‘Nightmare Eclipse.’ At some point, the universe starts writing its own satire.” — The Slap of Wisdom Incident Response Team, updating Defender to defend against Defender