Security researcher Nightmare Eclipse, who has shared several zero-day vulnerabilities, had their entire GitHub account and all repositories taken down.
They have now moved everything to a new GitLab profile at
In a signed message on their blog, they accuse Microsoft of defaming them, mishandling vulnerability reports like CVE-2026-45585, revoking their MSRC access, and quietly patching issues without collaborating.
They point to July 14 as an important date when they may release more documents or take things further.
The post also mentions two other vulnerabilities called UnDefend (CVE-2026-45498) and RedSun (CVE-2026-41091).