Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Halts Researcher After GitHub Suspension

GitLab Halts Researcher After GitHub Suspension

Posted on May 27, 2026 By CWS

The security researcher known as Nightmare-Eclipse has faced suspension from both GitLab and GitHub, with the latter occurring just days earlier. This action comes as a result of a controversial zero-day vulnerability campaign against Microsoft.

GitLab’s Recent Suspension

On May 26, 2026, GitLab suspended the account of the researcher Nightmare-Eclipse. This decision follows GitHub’s termination of the same account around May 23. The swift action by GitLab reflects the severity of the situation, as the researcher had been using the platform to replicate content previously hosted on GitHub.

The repositories on GitLab included six exploit tools targeting Windows Defender, extending their availability even after GitHub’s initial ban. This has raised significant concerns within the cybersecurity community regarding the implications for Microsoft’s security systems.

Origins of the Controversy

The campaign by Nightmare-Eclipse began on April 2, 2026, and was reportedly fueled by dissatisfaction with Microsoft’s Security Response Center. The researcher claimed that the center had not adequately responded to security disclosures.

Among the proof-of-concept tools released were BlueHammer, RedSun, and UnDefend. These tools demonstrated vulnerabilities within Windows Defender, including privilege escalation and unaddressed security flaws, which caught the attention of the cybersecurity industry.

Impact and Reactions

Huntress Labs reported the active use of these tools by threat actors as early as April 10, 2026. Attackers used these exploits to elevate privileges and execute malicious activities by disguising them with benign filenames.

Despite some patches issued by Microsoft, not all vulnerabilities have been addressed. The situation has sparked debate over ethical disclosure practices and the responsibilities of both researchers and platforms.

Nightmare-Eclipse has announced plans for a major disclosure event on July 14, 2026, hinting at more revelations to come. This has heightened discussions around platform accountability and the ethical implications of such disclosures.

For more updates, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:CISA, Cybersecurity, ethical disclosure, exploit tools, GitHub, GitLab, Huntress Labs, Microsoft, MSRC, Nightmare-Eclipse, Patch Tuesday, security research, Vulnerability, Windows Defender, zero-day

Post navigation

Previous Post: Anthropic’s New Plugin Enhances Code Security
Next Post: Critical BIND 9 Vulnerabilities Threaten DNS Security

Related Posts

Halo Security Achieves SOC 2 Type 1 Compliance Halo Security Achieves SOC 2 Type 1 Compliance Cyber Security News
Cybersecurity Industry Gains .7 Billion to Develop Cutting-Edge Protection Technologies Cybersecurity Industry Gains $1.7 Billion to Develop Cutting-Edge Protection Technologies Cyber Security News
SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes Cyber Security News
Hackers Actively Attacking Linux SSH Servers to Deploy TinyProxy or Sing-box Proxy Tools Hackers Actively Attacking Linux SSH Servers to Deploy TinyProxy or Sing-box Proxy Tools Cyber Security News
Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution Cyber Security News
Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Exploited Gitea Code Injection Risk
  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Exploited Gitea Code Injection Risk
  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark