Tech News

Nightmare Eclipse Reveals His Identity and Details His Microsoft Dismissal

Ten Windows exploits published in five months, almost always within hours of Patch Tuesday. Since this weekend, we can put a name behind the Nightmare Eclipse pseudonym: Abdelhamid Naceri, a former MSRC researcher dismissed by Microsoft in September 2024. Here is what we know about his conflict with Microsoft.

It all began on April 2, 2026, with the disclosure of BlueHammer, a zero-day flaw in Microsoft Defender published on GitHub along with its exploit code. It was followed by RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, LegacyHive, ShieldBreak, and then ShieldCrash on September 8, which I discussed in my article on this Defender zero-day that bypasses the ShieldBreak patch. At present, three of these flaws are listed in the CISA KEV catalog.

For several months, a rumor has been circulating: Nightmare Eclipse would be a former Microsoft employee. For its part, the Redmond company has always refused to confirm this information. In contrast, Microsoft has taken a hard line against him, notably by warning him and deleting his GitHub account.

This weekend, Nightmare Eclipse decided to reveal his identity on his X account: Abdelhamid Naceri. He also published a long thread titled "Story time". The name is not unfamiliar: Abdelhamid Naceri, also known as halov, has been credited by the Zero Day Initiative since 2020, notably for a Windows lock screen authentication bypass (CVE-2021-26431) and for a privilege escalation technique via the Windows Installer service, which ZDI detailed on its blog in 2022.

A surprise meeting, then a short email

According to his account, Naceri was working in September 2024 on the Vulnerabilities and Mitigations team at MSRC in Germany. Then a meeting appeared on his calendar with Tom Gallagher, MSRC vice president of engineering. Nothing unusual, until he realized that an HR manager was also present. He was told that he was going to be dismissed, with the stated reason that he had harmed Microsoft customers. No further details were provided.

After several unanswered emails, he received a message from Tom Gallagher dated September 20, 2024. "The company has identified a potential security issue," it reads. "Our security team was concerned that you put the company and its customers at risk by sharing information about a vulnerability with external parties," the vice president continued, before mentioning a loss of trust and a "mutual separation". A severance agreement followed: accept or reject it within a week. In other words, Microsoft accused him of leaking vulnerability-related information from within the company while he was still employed by MSRC.

Source: X - Nightmare Eclipse

Still according to Naceri, no details were ever given to him: neither the identity of the third party nor the date of the alleged incident. During a second interview, Tom Gallagher reportedly told him that he was banned from Microsoft and that a negative reference would be written if he requested one. Then came the money question, with the severance compensation tied to his departure.

€20,000 offered by HR, then €27,000 from Microsoft's lawyer, while stressing that the researcher had only six months of seniority in the German entity. His previous two years in the UK, during which he worked for Microsoft, would not have been counted. After negotiation, the final offer reportedly reached €55,000, plus one year of salary and outplacement services. He refused everything, and he now considers that to have been a mistake.

A lawsuit in Germany and a six-figure bill

The official dismissal letter arrived in his mailbox, dated March 3, 2025.

Naceri took Microsoft to the Cologne labor court for unfair dismissal. Once again, before the judge, Microsoft reportedly refused to provide any details about the infamous security flaw. On the contrary, Microsoft allegedly attacked his personal situation: the researcher supposedly was not allowed to work in Germany. Yet his visa mentioned Microsoft, and so did the supplementary sheet of his residence permit, which the court eventually admitted.

At the end of roughly two years of proceedings, the court reportedly issued its decision: the dismissal was upheld and Naceri won almost nothing. This battle allegedly cost him more than $200,000. "If only I hadn't put my soul into this job with countless sleepless nights, I would have moved on," he says. According to him, his only request was to be allowed to stay in Germany, something Microsoft could easily have granted.

The researcher insists on one point: this was never about bug bounty rewards. "They fired me for no reason, it was never about the bounties," he summarizes. He presents the publication of the zero-days as a protest against the way he was dismissed, also in the name of employees laid off by Microsoft without explanation (let's remember that in 2 years, Microsoft laid off nearly 30,000 people).

He says he looked for a job but could not find one. Yet this man clearly has real talent: he did not identify so many Windows zero-day flaws by snapping his fingers.

At this time, Microsoft has not publicly responded to these statements, and I do not think Microsoft will comment. We now have a clearer picture of the origin of this conflict, even if we only have Abdelhamid Naceri's version of events, alias Nightmare Eclipse.

I tried to contact Nightmare Eclipse for additional information (including his plans for the future), but my email remained unanswered.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.