Ethical Hacking News
A prominent Microsoft 0-day hunter, Nightmare Eclipse, has released a new exploit called FalconFlank, which affects CrowdStrike's Falcon endpoint security platform. The exploit, a privilege escalation vulnerability, highlights the ongoing threat landscape in the cybersecurity sector. As vendors prioritize product security, researchers must stay vigilant and adapt to emerging threats. This incident serves as a reminder of the importance of information sharing and collaboration in the face of evolving cybersecurity risks.
Microsoft 0-day hunter Nightmare Eclipse has shifted his focus from targeting Microsoft products to other vendors, surprising many in the cybersecurity sector. A new zero-day bug, FalconFlank, was released by Nightmare Eclipse, affecting CrowdStrike's Falcon endpoint security platform with a privilege escalation vulnerability. The FalconFlank exploit takes advantage of the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon, affecting fully updated Windows 11 and Windows Server 2025 systems. Kevin Beaumont confirmed the exploit works, and warned that Nightmare's decision to target other vendors may prompt cybersecurity vendors to prioritize product security over hypothetical AI attacks. The incident highlights the ongoing threat landscape in the cybersecurity sector, with researchers finding new vulnerabilities in endpoint and antivirus products. Cybersecurity professionals are urging vendors to take immediate action to patch their products, as the emergence of Nightmare Eclipse's exploits underscores the importance of vendor collaboration and information sharing.
Prolific Microsoft 0-day hunter Nightmare Eclipse, a seasoned security researcher also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, has recently shifted his focus from targeting Microsoft products to other vendors. This development comes as a surprise, given his previous singular focus on exposing vulnerabilities in Microsoft systems.
In a recent move, Nightmare Eclipse released a new zero-day bug called FalconFlank, which affects CrowdStrike's Falcon endpoint security platform. The exploit, a privilege escalation vulnerability, takes advantage of the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This feature is designed to inspect Microsoft Office documents and strip potentially harmful macros, thereby preventing malicious code or dangerous payloads from executing when users open the document.
According to Nightmare Eclipse, the FalconFlank exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled. The proof-of-concept (PoC) exploit was published on GitHub, and Nightmare Eclipse noted that by the time the exploit was released, CrowdStrike would already have detections for it. Therefore, testers had to either add the exploit to exclusions or obfuscate the PoC and change the DLL load technique.
Kevin Beaumont, a security sleuth, confirmed that the FalconFlank exploit works, along with several other exploits released by Nightmare Eclipse over the past week. Beaumont expressed surprise at Nightmare's decision to branch out to other vendors, given the quality issues with endpoint security products. He noted that the emergence of Nightmare's exploits may prompt cybersecurity vendors to up their game and prioritize product security over hypothetical AI attacks.
FalconFlank follows other vulnerabilities in various endpoint and antivirus products discovered by Nightmare Eclipse in the past few days. These include HardBreacher, an elevation of privileges bug in Kaspersky's endpoint antivirus product, and PrettyPrague, an elevation of privileges vulnerability in Gen Digital's Avast antivirus software. The latter, dubbed PrettyPrague, allows an attacker to dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell.
The incident has sparked concerns among cybersecurity professionals, who are urging vendors to take immediate action to patch their products. CrowdStrike has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting and refer to the FalconFlank Tech Alert in the CrowdStrike support portal.
The emergence of Nightmare Eclipse's exploits highlights the ongoing threat landscape in the cybersecurity sector. As endpoint security products become increasingly sophisticated, researchers are finding new vulnerabilities that can be exploited by malicious actors. The incident serves as a reminder that cybersecurity vendors must prioritize product security and stay vigilant in the face of emerging threats.
In related news, researchers have noted that popular AI models such as ChatGPT, Claude, and Grok experienced overlapping availability issues, which were subsequently resolved. Meanwhile, other security news includes the discovery of a zero-day attack on Microsoft patches, which failed to address a vulnerability in on-prem SharePoint.
The incident also underscores the importance of vendor collaboration and information sharing in the cybersecurity sector. As Nightmare Eclipse continues to release exploits and vulnerabilities, cybersecurity professionals must remain vigilant and adapt to emerging threats. By prioritizing product security and staying informed, individuals and organizations can better protect themselves against the ever-evolving threat landscape.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Shared-Security-Nightmare-The-Emergence-of-Nightmare-Eclipse-and-the-CrowdStrike-Falcon-Exploit-ehn.shtml
https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318
https://imtr.net/article/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc-7fd8
Published: Thu Sep 3 14:04:11 2026 by llama3.2 3B Q4_K_M