LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied.
The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrClass.dat file in the SYSTEM context. LegacyHive lets an attacker mount another user's hive under their own Classes registry branch, and from there read and modify that account's COM settings and file associations. In practice it is a post-exploitation tool: by swapping the right entries, an attacker gets their own code to run with the victim's privileges on that victim's next login, up to and including an administrator.
The exploit needs local access and a standard user account. Unlike the original, the released version additionally requires credentials for a second standard user and the name of a third account, which can be an administrator. All supported Windows versions are affected, both desktop and server.
Microsoft said it is aware of the report and is investigating the validity and applicability of the claims. There is still no patch. LegacyHive is the ninth zero-day Nightmare Eclipse has published amid a long-running dispute with the company: the researcher claims the Microsoft Security Response Center (MSRC) ignored the reports, blocked accounts, and deleted exploit repositories. Microsoft, for its part, criticizes the release of exploits before fixes are available.
With no patch yet, a KQL threat-hunting query published by researcher Kevin Beaumont helps detect exploitation attempts.
Based on reporting by The Hacker News.
Written by
Read next
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers aMicrosoft Confirms RoguePlanet, a Defender 0-Day Dropped by a Feuding Researcher
A week after the exploit went public, Microsoft confirmed RoguePlanet (CVE-2026-50656), a Defender race-condition 0-day that escalates to SYSTEM, and promised a fix.
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets
Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million. The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator,