Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

    September 4, 2026

    Microsoft says some users can’t open the Teams desktop client

    September 4, 2026

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    September 4, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges
    News

    New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

    adminBy adminSeptember 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    CrowdStrike

    An anonymous security researcher who uses the “Nightmare Eclipse” handle released a CrowdStrike Falcon zero-day exploit named “FalconFlank” that lets attackers escalate privileges on up-to-date Windows systems.

    Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike’s endpoint security platform.

    Successful exploitation allows attackers to spawn a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon’s Office malicious macros remediation feature.

    “FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” Nightmare Eclipse said. “As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon.”

    When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company is investigating the researcher’s claims and advised customers to disable the Microsoft Office Windows policy setting that toggles the security software’s File Suspicious Macro Removal feature.

    “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” the spokesperson told BleepingComputer. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.”

    Although the company also shared this link to the tech alert regarding the FalconFlank zero-day exploit, the advisory is not public, and customers can access it only if they have an account on CrowdStrike’s support portal.

    CrowdStrike has yet to reply to a second email asking for a copy of the FalconFlank tech alert and whether a CVE ID has been assigned to the FalconFlank flaw.

    Kaspersky, Avast, Nvidia, and Microsoft zero-days

    This week, Nightmare Eclipse has also released privilege escalation zero-day exploits for Kaspersky Antivirus for Endpoint (named HardBreacher) and GenDigital Avast Antivirus (PrettyPrague), as well as a denial-of-service zero-day for Nvidia (named GreenSection) that will crash the system.

    Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by Nightmare Eclipse this week are real and work.

    Nightmare Eclipse has also disclosed multiple zero-day exploits targeting multiple Microsoft products since April, including Microsoft Defender, BitLocker, and various other Windows components.

    These Microsoft zero-days are known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While the LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws have since been fixed, the other security flaws remain zero-days and are still awaiting an official patch.

    After Nightmare Eclipse disclosed the first zero-days, Microsoft responded with warnings of legal action against people engaging in “malicious activity causing real harm to our customers,” prompting many to believe that the company was directly threatening the security researcher.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft says some users can’t open the Teams desktop client
    admin
    • Website

    Related Posts

    News

    Microsoft says some users can’t open the Teams desktop client

    September 4, 2026
    News

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    September 4, 2026
    News

    IDScan sued over alleged data breach affecting 153 million drivers

    September 4, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

    September 4, 2026

    Microsoft says some users can’t open the Teams desktop client

    September 4, 2026

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.