← All stories
● Covered by 3 sources · 10 reportsMedium impact7 negative3 neutral

Nightmare Eclipse Releases 'HardBreacher' Exploit for Kaspersky Endpoint Security

🔄 Updated 9d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Nightmare Eclipse released a PoC exploit for Kaspersky Endpoint Security.
  • The exploit, named HardBreacher, targets a privilege escalation vulnerability.
  • Kaspersky confirmed the issue is resolved via automatic updates.
  • The researcher has previously disclosed vulnerabilities in Microsoft products.
  • Chaotic Eclipse released a PoC for FalconFlank, a zero-day privilege escalation vulnerability.
  • FalconFlank affects CrowdStrike Falcon.
  • The vulnerability abuses malicious macro remediation in the Falcon Sensor.
  • The PoC works on Windows 11 25H2 and Windows Server 2025.
  • The Kaspersky vulnerability affects version 14.0.0.504.
  • CrowdStrike is investigating the FalconFlank vulnerability.
  • CrowdStrike advises customers to disable a specific Microsoft Office Windows policy setting.
  • Nightmare Eclipse is also known as Infinite Nightmare and MSNightmare.
  • Nightmare Eclipse released three new zero-day exploits last week.
  • PrettyPrague targets the Avast sandbox to spawn a shell with full system privileges.
  • PrettyPrague may also affect other GenDigital products, including AVG and Norton.
  • GenDigital fixed the PrettyPrague issue.
  • Chaotic Eclipse released a PoC for ShieldCrash, a zero-day vulnerability in Microsoft Defender.
  • ShieldCrash is a patch bypass for CVE-2026-69414 (ShieldBreak).
  • ShieldCrash allows arbitrary file reads as SYSTEM on all supported Windows versions.
  • Microsoft patched CVE-2026-69414 in Malware Protection Engine version 1.1.26080.3.
  • The ShieldCrash exploit was released after Microsoft's September 2026 Patch Tuesday updates.
  • ShieldCrash allows arbitrary file reads with System privileges.
  • The underlying ShieldCrash vulnerability can be exploited to gain full System privileges.
  • ShieldCrash is a bypass for ShieldBreak, released on August 2026 Patch Tuesday.
  • ShieldBreak was a bypass for RoguePlanet, a zero-day on June 2026 Patch Tuesday.
  • Microsoft patched RoguePlanet (CVE-2026-50656) on July 19.
  • Microsoft acknowledged ShieldBreak on August 14 and rolled out fixes on September 3.
  • Abdelhamid Naceri released a new zero-day exploit named BigDiskBuster.
  • BigDiskBuster allows standard users to block Microsoft Defender antivirus updates.
  • BigDiskBuster works on all supported Windows versions.
  • BigDiskBuster needs to run in the background to block Defender updates.
  • BigDiskBuster prevents Defender from performing platform and signature updates.
  • BigDiskBuster is similar to UnDefend.
  • The BigDiskBuster PoC is buggy and needs rewriting.
  • The BigDiskBuster exploit was released as part of an ongoing dispute with Microsoft.
  • Nightmare Eclipse revealed his identity as Abdelhamid Naceri.
  • Abdelhamid Naceri previously worked with Microsoft in the UK and Germany.
  • BigDiskBuster was published on GitHub on September 19.
  • BigDiskBuster prevents Microsoft Defender updates by filling all available disk space.
  • BigDiskBuster has no patch, CVE, or Microsoft advisory.
  • Abdelhamid Naceri was dismissed from Microsoft's Security Response Center in 2024.
  • Abdelhamid Naceri has been releasing exploits without coordinating with Microsoft since April.
  • Abdelhamid Naceri's earlier Defender exploits (BlueHammer, RedSun, UnDefend) were used in attacks.
  • CISA added BlueHammer, RedSun, and UnDefend to its Known Exploited Vulnerabilities catalog.
  • BigDiskBuster watches the C:\ drive for new directories under Defender.

New Exploit Targets Kaspersky Product

The security researcher known as Nightmare Eclipse has publicly released a new proof-of-concept (PoC) exploit, named "HardBreacher," which targets a privilege escalation vulnerability in Kaspersky Endpoint Security. This disclosure follows a pattern of the researcher releasing zero-day exploits, often after expressing frustration with vendor vulnerability handling processes.

Vulnerability Details and Impact

The HardBreacher exploit specifically targets a privilege escalation flaw within Kaspersky's endpoint security product. According to Nightmare Eclipse, successful exploitation can lead to the operating system becoming unstable, with the ability to disrupt Kaspersky's UI process and manipulate file access controls. The researcher noted the PoC was not fully refined but demonstrated the vulnerability's potential impact.

Kaspersky's Response

In response to the public disclosure, Kaspersky confirmed that the underlying security issue has been addressed. The company stated that a fix has been delivered to users through an automatic update, and users can also manually trigger a database update to ensure their systems are protected. This rapid response aims to mitigate the risk posed by the publicly available exploit.

Researcher's History of Disclosures

Nightmare Eclipse, also known as Chaotic Eclipse, has a history of disclosing zero-day vulnerabilities and releasing PoC exploits, primarily for Windows and Microsoft Defender flaws. Previous exploits include "ShieldBreak" and "LegacyHive," both of which enabled privilege escalation. The researcher's motivation for public disclosure has been cited as dissatisfaction with how some vendors handle vulnerability reports, leading to a series of public releases of security flaws.

Updates

🕒 2026-09-22 · new reporting from The Hacker News
  • BigDiskBuster was published on GitHub on September 19.
  • BigDiskBuster prevents Microsoft Defender updates by filling all available disk space.
  • BigDiskBuster has no patch, CVE, or Microsoft advisory.
  • Abdelhamid Naceri was dismissed from Microsoft's Security Response Center in 2024.
  • Abdelhamid Naceri has been releasing exploits without coordinating with Microsoft since April.
  • Abdelhamid Naceri's earlier Defender exploits (BlueHammer, RedSun, UnDefend) were used in attacks.
  • CISA added BlueHammer, RedSun, and UnDefend to its Known Exploited Vulnerabilities catalog.
  • BigDiskBuster watches the C:\ drive for new directories under Defender.
🕒 2026-09-22 · new reporting from SecurityWeek
  • Nightmare Eclipse revealed his identity as Abdelhamid Naceri.
  • Abdelhamid Naceri previously worked with Microsoft in the UK and Germany.
🕒 2026-09-22 · new reporting from BleepingComputer
  • Abdelhamid Naceri released a new zero-day exploit named BigDiskBuster.
  • BigDiskBuster allows standard users to block Microsoft Defender antivirus updates.
  • BigDiskBuster works on all supported Windows versions.
  • BigDiskBuster needs to run in the background to block Defender updates.
  • BigDiskBuster prevents Defender from performing platform and signature updates.
  • BigDiskBuster is similar to UnDefend.
  • The BigDiskBuster PoC is buggy and needs rewriting.
  • The BigDiskBuster exploit was released as part of an ongoing dispute with Microsoft.
🕒 2026-09-10 · new reporting from SecurityWeek
  • ShieldCrash allows arbitrary file reads with System privileges.
  • The underlying ShieldCrash vulnerability can be exploited to gain full System privileges.
  • ShieldCrash is a bypass for ShieldBreak, released on August 2026 Patch Tuesday.
  • ShieldBreak was a bypass for RoguePlanet, a zero-day on June 2026 Patch Tuesday.
  • Microsoft patched RoguePlanet (CVE-2026-50656) on July 19.
  • Microsoft acknowledged ShieldBreak on August 14 and rolled out fixes on September 3.
🕒 2026-09-09 · new reporting from The Hacker News, BleepingComputer
  • Chaotic Eclipse released a PoC for ShieldCrash, a zero-day vulnerability in Microsoft Defender.
  • ShieldCrash is a patch bypass for CVE-2026-69414 (ShieldBreak).
  • ShieldCrash allows arbitrary file reads as SYSTEM on all supported Windows versions.
  • Microsoft patched CVE-2026-69414 in Malware Protection Engine version 1.1.26080.3.
  • The ShieldCrash exploit was released after Microsoft's September 2026 Patch Tuesday updates.
🕒 2026-09-07 · new reporting from SecurityWeek
  • Nightmare Eclipse is also known as Infinite Nightmare and MSNightmare.
  • Nightmare Eclipse released three new zero-day exploits last week.
  • PrettyPrague targets the Avast sandbox to spawn a shell with full system privileges.
  • PrettyPrague may also affect other GenDigital products, including AVG and Norton.
  • GenDigital fixed the PrettyPrague issue.
🕒 2026-09-04 · new reporting from BleepingComputer
  • CrowdStrike is investigating the FalconFlank vulnerability.
  • CrowdStrike advises customers to disable a specific Microsoft Office Windows policy setting.
🕒 2026-09-03 · new reporting from The Hacker News
  • Chaotic Eclipse released a PoC for FalconFlank, a zero-day privilege escalation vulnerability.
  • FalconFlank affects CrowdStrike Falcon.
  • The vulnerability abuses malicious macro remediation in the Falcon Sensor.
  • The PoC works on Windows 11 25H2 and Windows Server 2025.
  • The Kaspersky vulnerability affects version 14.0.0.504.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A zero-day proof-of-concept tool named BigDiskBuster was released on GitHub, which prevents Microsoft Defender from updating by consuming all available disk space. This tool, created by a former Microsoft security researcher, has no current patch or CVE, potentially leaving systems vulnerable to outdated Defender definitions.

The researcher known as Nightmare Eclipse, now identified as Abdelhamid Naceri, released a new proof-of-concept exploit called BigDiskBuster for Microsoft Defender. This exploit prevents Defender from updating its platform and signatures, working on all supported Windows versions.

Security researcher Abdelhamid Naceri released a new zero-day exploit, named BigDiskBuster, that allows standard users to block Microsoft Defender antivirus updates on all supported Windows versions. This exploit prevents Defender from performing platform and signature updates, potentially leaving systems vulnerable.

Security researcher Nightmare Eclipse released 'ShieldCrash', a new zero-day exploit for Microsoft Defender that allows privilege escalation on fully patched Windows systems. This exploit bypasses previous patches for similar vulnerabilities, indicating an incomplete fix for the underlying security flaw.

A security researcher released a new zero-day exploit named "ShieldCrash" for Microsoft Defender, which grants SYSTEM access. This exploit was disclosed immediately after Microsoft's September 2026 Patch Tuesday updates, indicating a critical vulnerability in the widely used security software.

Security researcher Chaotic Eclipse released a proof-of-concept (PoC) for ShieldCrash, a new zero-day vulnerability in Microsoft Defender that bypasses the recent patch for CVE-2026-69414 (ShieldBreak). This bypass allows for arbitrary file reads as SYSTEM on all supported Windows versions, indicating that Microsoft's initial fix was incomplete.

Security researcher Nightmare Eclipse disclosed three new zero-day exploits affecting products from Avast, CrowdStrike, and Nvidia. These exploits allow privilege escalation or impact shared memory, prompting vendors to issue advisories and patches.

A security researcher released a zero-day exploit, "FalconFlank," affecting CrowdStrike Falcon on Windows 11 and Windows Server, enabling attackers to gain SYSTEM privileges. The vulnerability abuses CrowdStrike Falcon's Office malicious macros remediation feature. CrowdStrike is investigating and advises customers to disable a specific Microsoft Office Windows policy setting.

A security researcher released a proof-of-concept (PoC) for "FalconFlank," a zero-day privilege escalation vulnerability affecting CrowdStrike Falcon. This vulnerability abuses malicious macro remediation in the Falcon Sensor, allowing for privilege escalation on Windows 11 and Windows Server 2025 systems.

Security researcher Nightmare Eclipse released a proof-of-concept exploit, dubbed "HardBreacher," targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. Kaspersky stated that the underlying issue has been resolved via an automatic update, or users can trigger a database update manually. This exploit highlights ongoing concerns about endpoint security product vulnerabilities and the impact of public zero-day disclosures.