LIVE · cybersecurity feed
Live wire
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security Flaws
security

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

A shared security 'Nightmare'

zeroday.news ·

A security researcher known as Nightmare Eclipse, who has previously focused on Microsoft vulnerabilities, has released proof-of-concept (PoC) exploit code for a new zero-day privilege escalation vulnerability affecting CrowdStrike's Falcon endpoint security platform. The vulnerability, dubbed "FalconFlank," was published on Thursday and reportedly abuses a feature within CrowdStrike Falcon designed to remediate malicious macros in Microsoft Office documents.

According to Nightmare Eclipse, FalconFlank exploits the automated security tool that inspects Microsoft Office documents and strips out suspicious macro code. The researcher claims the PoC works on fully updated Windows 11 25H2 and Windows Server 2025 systems, provided CrowdStrike Falcon is running with "Phase 3 - Optimal Protection" and the malicious macro removal feature is enabled.

CrowdStrike confirmed it is actively investigating the claims and has advised customers to disable the "Microsoft Office File Suspicious Macro Removal Windows policy setting." The company stated that customers remain protected through the "Cloud Anti-malware for Microsoft Office Files settings" and referred them to a "FalconFlank Tech Alert" in its support portal.

The researcher noted in a GitHub README that CrowdStrike would likely have detections for the exploit by the time of its release, suggesting that testers might need to add it to exclusions or obfuscate the PoC to bypass detection. An independent security researcher confirmed the exploit's functionality, along with several others recently released by Nightmare Eclipse.

This release marks a shift for Nightmare Eclipse, who has recently published vulnerabilities in other endpoint and antivirus products. Among these is "HardBreacher," an elevation of privileges bug affecting Kaspersky's endpoint antivirus product, specifically version 14.0.0.504 on a fully patched Windows 11 25H2 system. Kaspersky has not yet commented on this vulnerability.

Another zero-day, "PrettyPrague," targets Gen Digital's Avast antivirus software. This vulnerability is described as capable of dumping the SAM database by exploiting a flaw in Avast Sandbox and spawning a full SYSTEM shell. Gen Digital acknowledged the vulnerability affecting a subset of its products, including Avast Antivirus, and stated it is actively developing a patch.

Nightmare Eclipse also recently disclosed "GreenSection," an Nvidia memory corruption zero-day vulnerability. However, an independent analysis suggests this particular exploit primarily causes system crashes. Nvidia has not responded to inquiries regarding GreenSection.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

vulnerabilitycritical

HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]

phishing

Outsider Phishing Kit Survives Takedown With 700 New Pages

Outsider phishing kit generated 700 new pages after a Google-led disruption

security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

breach

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United Sta