← Back to Feed
LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation
July 27, 2026 · LevelBlue SpiderLabs · Severity: LOW
The article discusses LegacyHive, a Windows proof-of-concept vulnerability published by the Nightmare-Eclipse disclosure actor. It exploits offline registry manipulation to abuse profile initialization, potentially enabling persistence or privilege escalation on Windows systems.
Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC) released shortly after Microsoft's July 2026 Patch Tuesday.
Key Takeaways
- LegacyHive is a new Windows zero-day proof-of-concept exploiting profile initialization.
- It abuses offline registry manipulation to achieve persistence or privilege escalation.
- The disclosure follows a series of Windows vulnerabilities from the Nightmare-Eclipse actor.