AuraTracer智迹闻
中文

EVENT DOSSIER

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

2026-09-04 02:08 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated

On September 3, 2026, security researcher Nightmare Eclipse disclosed zero-day exploit code for the CrowdStrike Falcon endpoint security platform, named ‘FalconFlank’. This exploit exploits Microsoft Office’s malicious macro repair function to gain elevated privileges, and requires the use of Windows 11 25H2 and specific system patches. CrowdStrike advised customers to disable related policy settings, but noted that cloud antivirus capabilities still provide protection. Kevin Beaumont confirmed the effectiveness of this vulnerability and stated that Nightmare Eclipse is shifting its focus from Microsoft products to other vendors, including Kaspersky, Gen Digital, and Nvidia products.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
CrowdStrikeFalconFlankKevin BeaumontNightmare Eclipse

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
CrowdStrike × FalconFla…1CrowdStrike × Kevin Bea…1CrowdStrike × Nightmare…1FalconFlank × Kevin Bea…1FalconFlank × Nightmare…1Kevin Beaumont × Nightm…1

SignalsSIGNALS

Keyword heat
  • Nightmare Eclipse1
  • CrowdStrike1
  • FalconFlank1
  • Kevin Beaumont1

All reports (1)SOURCES

T The Register en 2026-09-04 02:08

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

安全研究员 Nightmare Eclipse 发布针对 CrowdStrike Falcon 端点安全平台的零日漏洞 FalconFlank。该漏洞利用 Microsoft Office 恶意宏修复功能实现提权,需配合 Windows 11 25H2 及特定系统补丁使用。CrowdStrike 建议客户禁用相关策略设置,但表示云反病毒功能仍提供保护。Kevin Beaumont 证实该漏洞有效,并指出 Nightmare Eclipse 正从单一针对 Microsoft 转向其他厂商,包括 Kaspersky、Gen Digital 和 Nvidia 的产品。