Related Threat Clusters
-
Nightmare-Eclipse Tools Exploit FortiGate VPNs in Live Attacks
A recent intrusion campaign utilized the Nightmare-Eclipse privilege escalation tools, specifically BlueHammer, RedSun, and UnDefend, following unauthorized access through compromised FortiGate SSL VPN credentials. This…
2 articles · Updated April 22, 2026 -
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
227 articles · Updated April 30, 2026 -
Microsoft Edge and SharePoint Server Vulnerabilities Under Active Exploitation
On April's Patchday, Microsoft addressed over 160 security vulnerabilities, including critical issues in Edge and SharePoint Server. Attackers are actively exploiting CVE-2026-32201 in SharePoint for spoofing attacks,…
71 articles · Updated April 15, 2026 -
Zero-Day Vulnerability in VS Code Allows GitHub Token Theft via Malicious Links
A newly disclosed zero-day vulnerability in Visual Studio Code (VS Code) enables attackers to steal GitHub OAuth tokens by tricking users into clicking a malicious link. The flaw exploits the webview message-passing…
14 articles · Updated June 3, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Ransomware Gangs Exploit Microsoft Defender BlueHammer Flaw for Attacks
Ransomware gangs are actively exploiting a high-severity vulnerability in Microsoft Defender, tracked as CVE-2026-33825 and nicknamed BlueHammer. This flaw allows local attackers to bypass access controls and escalate…
3 articles · Updated July 1, 2026 -
New Windows Zero-Day Vulnerabilities: YellowKey and GreenPlasma Exploits Released
Security researcher Nightmare-Eclipse has disclosed two critical zero-day vulnerabilities affecting Windows 11 and Windows Server 2022/2025. The first, YellowKey, allows attackers to bypass BitLocker encryption,…
42 articles · Updated May 13, 2026 -
New Windows Zero-Day 'ShieldBreak' Exploits Microsoft Defender Flaw
Security researcher Nightmare Eclipse has disclosed a new zero-day vulnerability named ShieldBreak, which allows attackers to gain SYSTEM-level privileges on fully patched Windows 10, Windows 11, and Windows Server…
55 articles · Updated August 12, 2026 -
MiniPlasma Zero-Day Exploit Grants SYSTEM Access on Patched Windows Systems
A newly discovered Windows zero-day exploit, named MiniPlasma, allows attackers to gain SYSTEM-level privileges on fully patched Windows systems. The exploit targets the cldflt.sys Cloud Filter driver, specifically the…
30 articles · Updated May 18, 2026 -
Nightmare-Eclipse Banned from GitHub and GitLab for Zero-Day Exploits
The anonymous security researcher known as Nightmare-Eclipse has been banned from both GitHub and GitLab due to the release of multiple unpatched Windows vulnerabilities. GitHub terminated the account on May 25, 2026,…
124 articles · Updated May 27, 2026
Recent Intelligence Reports
- A Shared Responsibility Protecting Customers Through Coordinated Vulnerability Disclosure — www.microsoft.com · August 18, 2026
- BlueHammer — www.cyderes.com · August 13, 2026
- Microsoft — Theregister · August 12, 2026
- Microsoft — Theregister · August 12, 2026
- Disgruntled Researcher Discloses New Zero-Day in Windows Antivirus — Uk.Pcmag · August 12, 2026
- New Microsoft Defender 'ShieldBreak' zero — Bleepingcomputer · August 12, 2026
- Microsoft Reins in RoguePlanet Zero — Darkreading · July 9, 2026
- Defender Zero — Techtimes · July 9, 2026