Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
2026-09-04 02:08Cybersecurity🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated
On September 3, 2026, security researcher Nightmare Eclipse disclosed zero-day exploit code for the CrowdStrike Falcon endpoint security platform, named ‘FalconFlank’. This exploit exploits Microsoft Office’s malicious macro repair function to gain elevated privileges, and requires the use of Windows 11 25H2 and specific system patches. CrowdStrike advised customers to disable related policy settings, but noted that cloud antivirus capabilities still provide protection. Kevin Beaumont confirmed the effectiveness of this vulnerability and stated that Nightmare Eclipse is shifting its focus from Microsoft products to other vendors, including Kaspersky, Gen Digital, and Nvidia products.