introduction
you've probably heard of nightmare eclipse if you’ve been following cybersecurity at all these past few months. chaotic eclipse, dead eclipse, msnightmare - same person, new account every time microsoft bans the last one
since april he's been casually dropping windows exploits: bluehammer, yellowkey, redsun, undefend, greenplasma, miniplasma, rogueplanet, legacyhive, and shieldbreak on august's patch tuesday. almost all of then pointed at defender or something right next to it, which isnt a coincidence (!)
and people were mostly on his side for a reason, msrc had a reputation. once his case started gaining numbers, other researchers started posting their own stories about their reports getting outright ignored, downgraded, or quietly patched with no reply
i probably knew about it as much as you do, until last evening, when he opened a discord server...
what everyone knew
it started on march 26th 2026 with a blog post:
But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.
then a week later he dropped bluehammer and the campaign was on
the post never actually says what the agreement was. journalists filled that in and it was a fair guess, because everything else he said publicly pointed the same way. from his may reply to microsoft:
You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so.
so the story became: researcher reports bugs, msrc mishandles them, doesnt pay, deletes his account, researcher retaliates
microsoft answered on may 28th with an msrc post - "A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure". the vulnerabilities werent responsibly disclosed, customers were being put at risk, and they brought up the digital crimes unit and were working with law enforcement. they faced so much backslash that within days they put out a softer version: no intention of pursuing people doing or publishing security research, plus an admission that some of their interactions with researchers had fallen short
discord server
on august 18th, around 8:42 pm cest, the twitter account everyone attributes to him posted an invite


so i joined. there were bit more than 200 members, few text channels, one of them being called questions-that-may-or-may-not-be-answered (which aged well)
i kept running Tyrrrz's DiscordChatExporter over the channels every so often, because servers like this dont tend to last
the microsoft story
at 9:32 pm he opened a thread. first message: "The Microsoft story"
someone asked how he even talks to microsoft. email, something encrypted?
there it is
msrc. the same msrc everyone assumed he'd been fighting from the outside as some external reporter
getting fired
he's got a calendar invite from a new senior person, so he first thought it was an introduction, till he joined to find hr in the call. he was told he'd done things that "harmed microsoft customers", asked what things, and got told they werent telling him
this was october 2024, which somebody in the channel noticed straight away:
so about eighteen months between getting fired and the first exploit going out
he refused 20k. their lawyer wrote to him pointing out he'd only been there six months and that this was a great severance (their words), so he refused that too, then refused 27k
the thing he keeps circling back to isnt the money though, its the three years he spent "rawdogging" work, and nobody telling him what he actually did
a few other bits came out later in the thread. he says he was up for a promotion at the time ("then they revoked my promotion and fired me"), that it wasnt a layoff round and he "got picked out of everyone", and that his own manager wasnt told until the day before
he begged gallagher for another meeting just to find out the reason for his firing. he got one:
blacklisted, a horrible reference if he ever asked for one, and then an email later on with the only concrete accusation he says he ever got
access
he thinks it was bait - that they left him logged in hoping he'd do something they could use against him
i said in the channel that it couldve just been the two week kündigungsfrist under §622(3) BGB if he was still in probezeit, which would explain the account staying alive without anyone planning anything
then he gave the dates:
official termination letter march 3rd 2025, last working day june 30th 2025 - about four months between them, so whatever those two weeks were, they werent a notice period
german law wouldnt require microsoft to leave a suspected insider sitting on source code during any of it either. they couldve cut the access on day one and just paid him to sit at home, thats the normal way to do it
court
he says he didnt want to sue (waste of time and resources against microsoft, in his words), everyone around him pushed him into it. the hearing was may 2025
so he sued. and then microsoft filed their defence:
suprisingly, they argued his work authorization. his residence permit reads NOT AUTHORIZED TO WORK, SEE ADDITIONAL SHEET, which is completely normal, the permit isnt where the permission lives. the additional sheet said "Authorized to work for Microsoft Deutschland GMBH"
so he brought them the additional sheet, and then:
they'd asked for the documents in his work email, which they had already cut off a long time before. the court apparently called that a miscommunication, which is one word for it
then microsoft argued he'd threatened them, with a witness:
when i asked about their court position, he paraphrased it with a racial slur about himself, twice. guess that means "they had nothing"
thats where he stopped fighting, and a month later bluehammer happened:
my questions
german employment law has a thing for this: under §626(2) BGB, if youre fired without notice and you request the reason, the employer has to give it to you in writing without delay. so i asked whether it was a fristlose kündigung (german for termination without notice) and whether he'd ever requested it:
the channel kept getting locked and unlocked so i dm'd him too, about whether he ever tried a neutral third party (cert/cc or similar) before any of this went public:
i (unfortunately) also live in germany, so i was wondering, was that a fristlose kündigung? asking because under §626(2) BGB, if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?
in the thread he put it shorter - "If you go whine about it to anyone, no cares"
then the one i actually wanted. did microsoft ever name the third party in court?
so by his account microsoft privately accused him of handing vulnerability information to someone, then refused to say who or when. and then never brought it up in court, where you'd expect them to justify the firing. someone asked whether the court documents are public and he said "not yet"
not the bounty
at 11:05 pm cest i asked whether microsoft ever produced any evidence for the leak claim:
if thats true then every article written about this had the motive wrong, and i'd only ever read the articles
so i asked the obvious follow up:
and then nothing. no answer, and a couple minutes later the server just wasnt in my sidebar anymore. turns out servers like this really dont tend to last. on twitter shortly after: "Closed, too much headache"
fact checking
so how much of this can we actually check? not a lot. i was in the server, the invite came off the twitter account everyone attributes to him, and the exports are sitting on my disk, which is enough to say the q&a happened. who was doing the typing is beyond me
the ex employee thing was already the leading theory before any of this. the verge had it on may 30th, krebs on june 9th, and when the register asked microsoft straight out on may 28th whether he was current or former staff, they just didnt answer. the new bit is that he said it himself, and gave a team and a job title
lots of write ups say he worked there from september 2022 to june 2025, and they all point at krebs and the register as the source. some add that it came off a linkedin profile and a hackerone account belonging to whoever microsoft credited those bugs to
so i went and read both. its not in there. all thats in there is him claiming to be an ex employee and microsoft refusing to comment, so i genuinely dont know where the dates came from
his own version (three years, ending 30 june 2025) lines up with them. but that could just as easily mean he read the same blogs everyone else did
some of it is just wrong though. he calls tom gallagher his CISO. gallagher is vp of engineering at msrc, and microsoft's global ciso is igor tsyganskiy (who took it over from bret arsenault). in the main channel he walked it back a bit, and somebody fact checked him live:
so "CISO" appears to be shorthand for whoever sat at the top of his reporting line. microsoft has handed that title out to a few people since anyway (theres operating cisos and a deputy ciso for europe now), so it doesnt mean just one person. "new" is still odd for someone with about 25 years there, and c0z was right to pull the linkedin on him
his dates dont quite line up either. he says he gave up on the court thing "that March last year", then that bluehammer happened the april after. but bluehammer went out in april 2026, and he was saying this in august 2026, so "last year" would put march a full year before that. either he meant march 2026 or those two things are thirteen months apart rather than one
microsoft's lawyer told him he'd only been there six months, he says three years. both can be true. the visa sheet names "Microsoft Deutschland GMBH" specifically. so if he moved onto the german payroll partway through, that job would only be six months old, while microsoft as a whole is still three (?)
and then theres this, fourteen minutes before he started the story:
so he told a channel full of strangers that some of what he posts publicly is made up, gave a reason for it, and an hour later told them a ninety minute first person story
everything else has no document attached to it, and he says the court file isnt public "yet"
what i think
this is all guesswork
it doesnt look like money to me. he turned down 20,000€, then turned down 27,000€, and if this was about getting paid he'd have taken the second offer and gone. what he keeps coming back to is that nobody would tell him what he did, and two years on he's still saying "still don't understand wtf did i do wrong"
that explains the part i never got. hes been attacking microsoft for months and complaining they wont talk to him, at the same time. if all you wanted was to hurt them, why would you care if they answer
and look what the campaign gives him. he has something microsoft doesnt have, and he gets to decide when it lands. then they have to react. rogueplanet went out on june's patch tuesday, legacyhive right after july's, shieldbreak on august 11th. microsoft can move most dates around. it cant move patch tuesday
i dont buy "this is their decision not mine" though. he knew what dropping those would do, saying microsoft made him doesnt really change that. cisa has bluehammer, redsun and undefend on its known exploited list, and marks bluehammer as having known ransomware use. huntress watched someone run all three against a real company back in april, though none of them appears to have worked there
as for why he kept the firing quiet for five months, i genuinely dont know, and thats the question that got no answer. maybe "researcher who got screwed over by the bounty process" just sounds a lot better than "ex employee with a grudge". maybe the case was still live and someone told him to shut up. i dont know
im not putting the full exports up. theres a couple hundred people in there who just came to ask questions
hes also not doing great. he talked about a fiancee who left him days before the wedding, said he has no income, and mentioned being high on benzos at some point. and he still has no idea what he did wrong, two years later
i hope he gets his answer at some point, and that things start going better for him soon
update
august 19th, 7:30 pm. i was finishing this article when he posted something on twitter suggesting that he had taken an overdose

like i said above, he wasnt doing well, and it looks like its gotten worse since. ill update this if anything changes
august 20th and 21st. the follow-up posts suggest the august 19th incident was not fatal, though he was still in crisis:


comments
0 comments