GitLab Suspends Nightmare-Eclipse After GitHub Ban Over Windows Exploit Releases
GitLab has suspended the account of Nightmare-Eclipse, the controversial Windows exploit researcher who moved there after GitHub terminated their account days earlier. The bans follow a string of public exploit releases targeting Microsoft Defender and other Windows security components.
According to Cybernews, GitLab blocked the account on May 26, 2026, after GitHub terminated Nightmare-Eclipse’s account around May 23. The GitLab account had reportedly mirrored exploit repositories that were previously hosted on GitHub.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The case has quickly moved beyond a platform moderation dispute. The researcher’s public releases have become part of an active security debate about coordinated vulnerability disclosure, vendor response timelines, code-hosting rules, and the real-world risk of publishing working exploit tools.
What Happened to the Nightmare-Eclipse Accounts
Nightmare-Eclipse, also referenced in some reports as Chaotic Eclipse, became widely known in April 2026 after publishing tools linked to Windows Defender vulnerabilities. The releases included BlueHammer, RedSun, and UnDefend, along with other Windows security-related research.
The GitHub ban removed the researcher’s original repositories from a Microsoft-owned platform. The move to GitLab gave the material another hosting path, but that did not last long. Cybernews reported that both platforms removed the published repositories after the suspensions.
That has not fully contained the material. As often happens with high-profile exploit releases, copies and forks can spread quickly once code becomes public. This creates a challenge for platforms that want to limit harm without turning enforcement into a publicity event.
| Event | Reported timing | Why it matters |
| Public exploit releases begin | April 2026 | Nightmare-Eclipse releases tools targeting Windows security components |
| BlueHammer gets a CVE and patch | April 2026 | Microsoft Defender privilege escalation flaw enters public vulnerability tracking |
| GitHub account terminated | Around May 23, 2026 | The original hosting path disappears |
| GitLab account suspended | May 26, 2026 | The mirror account is blocked days later |
Why the Windows Defender Exploits Raised Alarm
The first major tool, BlueHammer, was linked to CVE-2026-33825. The NVD entry for CVE-2026-33825 describes the flaw as an access-control issue in Microsoft Defender that allows an authorized attacker to elevate privileges locally.
The same vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog on April 22, 2026, with a required action date of May 6 for affected federal civilian agencies. That made BlueHammer more than a public proof-of-concept story. It became an officially tracked exploited vulnerability.
Two later Defender issues also entered public tracking. The NVD entry for CVE-2026-41091 describes an improper link-resolution issue in Microsoft Defender that can allow local privilege escalation, while CVE-2026-45498 tracks a Microsoft Defender denial-of-service vulnerability.
Huntress Saw the Tooling in a Real Intrusion
The risk became more concrete when Huntress reported that it observed BlueHammer, RedSun, and UnDefend activity during a live intrusion investigation. The company linked the activity to compromised FortiGate SSL VPN access and suspicious binaries staged in user-writable directories.
Huntress said the observed activity included hands-on-keyboard reconnaissance and follow-on tunneling behavior. However, its analysis also included an important detail: the tools did not appear to have succeeded during that specific incident.
That distinction matters. Public exploit tooling can still increase risk even when one observed attack fails. Attackers can test, modify, and combine public tools with stolen credentials, VPN access, tunneling utilities, and other post-compromise techniques.
The Patch Timeline Has Changed
The original debate started with claims that Microsoft did not respond quickly enough to vulnerability reports. By late May, however, the patch picture had changed for some of the Defender issues.
The CVE-2026-41091 record shows the flaw in CISA’s Known Exploited Vulnerabilities catalog with a May 20, 2026 addition date and a June 3, 2026 due date. The CVE-2026-45498 record also shows CISA catalog inclusion on May 20 with the same June 3 remediation deadline.
For defenders, the takeaway is simple: this is no longer only a disclosure ethics story. It is a patching and exposure-management story. Systems running affected Defender components need verified remediation, not only default assumptions that automatic updates have already completed.
Why the Platform Bans Are Controversial
Security researchers often publish proof-of-concept code to prove impact, help defenders test exposure, or pressure vendors to patch. But working exploit tools can also help criminals move faster, especially when the flaws are already being probed in real environments.
That is why the Nightmare-Eclipse case has split opinion. Some see the bans as a necessary step to limit access to harmful code. Others argue that removing accounts after disclosure does not fix the underlying vulnerabilities and may push researchers toward less controlled channels.
The situation also highlights the power of developer platforms. GitHub and GitLab are not only code-hosting services. They shape how vulnerability research spreads, how quickly defenders can study public material, and how easily attackers can find reusable tooling.
What Organizations Should Do Now
Organizations should focus less on the researcher drama and more on Defender remediation. The CVE-2026-33825 record confirms Microsoft Defender local privilege escalation risk and CISA KEV inclusion, which means security teams should treat affected systems as high-priority patch targets.
Companies should also review logs for signs of post-compromise activity, especially if they saw recent VPN abuse, suspicious Defender behavior, unusual binaries in user-writable folders, or attempts to disable endpoint protection.
The Huntress investigation shows how public tooling can appear after initial access rather than as the first step. That means VPN hygiene, credential resets, endpoint detection, and privileged-access monitoring all matter alongside Microsoft Defender updates.
- Verify Microsoft Defender platform and engine updates across all endpoints.
- Prioritize systems that match CISA KEV deadlines.
- Review FortiGate SSL VPN and other remote-access logs for suspicious access.
- Search for unusual binaries staged in Downloads, Pictures, Temp, and other user-writable paths.
- Look for attempts to disable Defender, block updates, or tamper with security services.
- Rotate credentials if attacker access, tunneling tools, or privilege escalation attempts appear in logs.
- Track public exploit chatter, but avoid downloading unknown mirrors of removed repositories.
The Bigger Disclosure Debate Is Not Going Away
Nightmare-Eclipse has framed the releases as a response to Microsoft’s handling of vulnerability reports. Microsoft has generally pointed to coordinated vulnerability disclosure principles, while outside researchers continue to debate whether vendor response timelines are keeping up with modern exploitation speed.
The GitLab suspension may reduce access to one mirror, but it will not end the argument. Public exploit releases, platform bans, and delayed remediation claims will keep colliding when high-impact Windows vulnerabilities are involved.
For security teams, the safest response is practical rather than ideological. Track the CVEs, apply the fixes, monitor for abuse, and assume public exploit code can become attacker tooling quickly once it leaves the original researcher’s account.
FAQ
Nightmare-Eclipse, also referenced as Chaotic Eclipse in some reporting, is an anonymous security researcher who publicly released several Windows exploit tools in 2026, including tools tied to Microsoft Defender vulnerabilities.
GitLab reportedly suspended Nightmare-Eclipse after the researcher used the platform to mirror exploit repositories removed from GitHub. The repositories were tied to public Windows exploit releases, including Microsoft Defender-related tools.
Huntress reported that it observed BlueHammer, RedSun, and UnDefend activity during a live intrusion investigation. Huntress also said the tools did not appear to have succeeded in that specific incident.
Administrators should verify Microsoft Defender engine and platform updates, review CISA KEV-listed Defender vulnerabilities, check remote-access logs, search for signs of Defender tampering, and investigate suspicious binaries or tunneling tools on endpoints.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages