Dinner With a Threat Actor: A Source Relationship Worth Asking About
Since April 2026, an anonymous researcher operating under the handles Nightmare-Eclipse, Chaotic Eclipse, Dead Eclipse, and later MSNightmare has run a public, uncoordinated campaign against Microsoft. Seven Windows zero-days in roughly ten weeks, most targeting Microsoft Defender or adjacent security components, framed by the researcher as retaliation for how Microsoft handled prior bug reports and bounty payments.
The releases are real and independently confirmed. Huntress documented BlueHammer, RedSun, and UnDefend used in live intrusions. CISA added several to its Known Exploited Vulnerabilities catalog. Cyderes independently reproduced RoguePlanet on a fully patched Windows 11 host. GitHub and GitLab both terminated the researcher's accounts. Microsoft responded publicly through MSRC with a post titled "A shared responsibility," which prompted other named researchers, including Gabriel Landau, to come forward with their own complaints about how MSRC handles disclosure.
None of that is in dispute. This is about who has been covering it, and how.
In a post dated one day before the LegacyHive writeup, International Cyber Digest wrote, in first person: "Last month I took Nightmare-Eclipse out for dinner. He's the person behind all those Windows zero-day PoC drops." The post goes on to describe the meal in specific, personal detail: the researcher choking on unexpected fish bones, picking the fish apart methodically, being "a bright young fella... very calm and professional." ICD then writes: "after hearing his story, it sounds to me like Microsoft really screwed him over and sent him off the rails," and closes with: "I'm not allowed to say more, but this story still hasn't ended."
This is a first-person, self-published account of an in-person meeting with the anonymous threat actor at the center of ICD's own ongoing coverage. Not an inference, not a jab, ICD's own words, posted under its own verified account.
The line "I'm not allowed to say more" is the one worth sitting with longest.
This is not the only sign of familiarity. In the LegacyHive post the following day, ICD also noted that "Nightmare-Eclipse previously told us that vulnerability names are inspired by random events in his life," and that "LegacyHive" breaks from that convention. Noticing a pattern shift in someone's naming habits is not something you get from reading public GitHub drops. It requires paying close, continuous attention to how that person operates.
Timeline, for context:
- April 3, 2026: first release drops, opening what becomes a seven-exploit campaign against Microsoft Defender and adjacent Windows security components
- April–May: BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma follow in succession, all posted publicly on GitHub, framed by the researcher as retaliation over bounty and disclosure handling
- Mid-campaign: other researchers begin handing Nightmare-Eclipse vulnerabilities for free, starting with Bitskrieg, a Secure Boot and BitLocker bypass. ICD reported this as "a show of support" and "a reaction to how Microsoft treats researchers," evidence the researcher had earned sympathy across the community, not just from ICD
- May 23-24: GitHub terminates the account. A signed message threatens Microsoft, naming July 14 specifically
- Late May: GitLab removal follows. MSRC publishes a response titled "A shared responsibility." Other named researchers, including Gabriel Landau, come forward with their own complaints about MSRC's handling of past reports
- Early June: the researcher resurfaces under the alias MSNightmare with RoguePlanet, a seventh exploit independently reproduced by Cyderes on a fully patched Windows 11 host
- July 14-15: LegacyHive drops hours after July's Patch Tuesday, covered within a similar window by Cybernews, The Register, The Hacker News, Cybersecurity News, and ICD
What tempers this: every major release in this campaign was posted publicly by the researcher, with signed messages anyone could read. Multiple outlets covered the same material on similar timelines. ICD is not the only outlet with access to the exploits themselves. The distinguishing fact is not exclusivity over the drops. It is the two pieces of direct-contact evidence above: the quote about naming inspiration, and the tracked shift in that pattern.
International Cyber Digest has covered every major beat of this campaign, sometimes within hours of release, alongside outlets like The Hacker News, Cybernews, The Register, and Barracuda. The material itself, the exploits, the signed threats, the GitHub takedowns, was posted publicly by the researcher and available to any outlet. What is not public, and what the dinner post confirms exists, is a personal relationship between the outlet and the source it has covered for months. How long has this relationship existed. What was agreed to that ICD is "not allowed to say." Has it shaped what gets covered, or how.
International Cyber Digest's own "About" page states a preference for "primary sources, documents, technical evidence, reproducible analysis, and direct right-of-reply requests." The relationship described in the dinner post exists alongside that stated standard.
What this is not: an accusation of fabrication, collusion, or paid access. There is no evidence of any of that, and none is claimed here. The relationship exists. ICD said so, in its own words. Readers can reasonably ask what it involves.
Open questions for follow-up: how long has this contact existed. Has ICD ever held or delayed reporting at the researcher's request. Has the researcher ever corrected or directed ICD's framing of a release.
About the author:
Clayton Bax 𝕏 @BAXIMUSCYBER85 GITHUB: BAXIMUS855.GITHUB.IO onyxdigitalintelligence85@pm.me
OPEN FOR WORK
"I'd rather have questions that can't be answered than answers that can't be questioned. The first principle is that you must not fool yourself, and you are the easiest person to fool." -- Richard Feynman