Nightmare Eclipse Unveils New Microsoft Defender Exploit After Identity Exposure
Researchers and cybersecurity experts are closely monitoring the release of a new Microsoft Defender exploit by a researcher who has now revealed their real identity.
New Microsoft Defender Exploit Released
Nightmare Eclipse, a researcher who previously shared multiple Windows and Defender exploits, has disclosed their real identity as Abdelhamid Naceri. Naceri recently released a proof-of-concept exploit called BigDiskBuster, which targets Microsoft Defender. The tool, announced over the weekend, is described as similar to UnDefend and functions across all currently supported Windows versions. However, the GitHub repository for BigDiskBuster acknowledges the code remains unstable and requires further refinement.
Background on Abdelhamid Naceri
Naceri, whose vulnerability discoveries were highlighted in cybersecurity news years ago, previously worked with Microsoft in the UK and Germany. A public account of their departure from the company was shared via a now-deleted social media platform. According to Naceri, Microsoft terminated their employment abruptly without providing a clear rationale. The researcher claimed the company offered multiple financial settlement options, which they rejected in favor of seeking a formal explanation and assistance to remain in Germany.
“Microsoft presented inconsistent arguments during a German labor court proceeding challenging the termination,” Naceri said. “The court ultimately ruled in favor of the company, resulting in minimal compensation after a protracted and expensive legal battle.”
Legal Dispute with Microsoft
Naceri alleged that the dispute had a severe impact on their mental health, leading to hospitalization for psychiatric care. Additionally, Naceri clarified that previous assertions about Microsoft initiating legal action against them—amid broader controversy over the company’s threats against researchers disclosing zero-day vulnerabilities—were false. Microsoft has not yet responded to requests for comment on the BigDiskBuster exploit, and further updates will be provided if the company issues a statement.
Implications for Windows Security
The researcher’s disclosure of their identity and the release of the new exploit highlight ongoing tensions between independent security researchers and major technology firms. The technical details of BigDiskBuster, including its methodology and potential implications for Windows security, remain under scrutiny by the cybersecurity community.
The case underscores the complex relationship between researchers and corporations, as well as the challenges of balancing security disclosures with legal and ethical considerations.
