Urgent.News

What's breaking now, across thousands of outlets.

Tech

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

A shared security 'Nightmare'

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

Prolific security researcher Nightmare Eclipse has released a proof-of-concept (PoC) exploit, FalconFlank, targeting CrowdStrike’s Falcon endpoint security platform. This vulnerability is a privilege escalation issue that exploits the Microsoft Office malicious macros remediation feature within CrowdStrike Falcon. The security tool scrutinizes Microsoft Office documents and removes potentially harmful macros, aiming to prevent malicious code from executing.

However, the FalconFlank exploit takes advantage of this process, allowing attackers to escalate their privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems with CrowdStrike Falcon Phase 3 – Optimal Protection and the malicious macro removal feature enabled. Additionally, Nightmare Eclipse has published exploits for other vulnerabilities, including HardBreacher in Kaspersky’s endpoint antivirus and PrettyPrague in Avast Antivirus.

Security experts, such as Kevin Beaumont, have confirmed the functionality of Nightmare’s exploits, urging cybersecurity vendors to improve their products' security and stop relying on hypothetical AI attacks.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Handoff is Where the Agent Dies: 3 Patterns That Fix It

Your multi_agent pipeline works fine in testing. Then you deploy it and watch it fail: Agent A finishes its task and "passes" to Agent B.

  • Artifact Chaining shares evidence of agent's work during handoff
  • Contract Testing validates received artifacts against defined contract
  • Shared Memory Repository enables agents to maintain shared knowledge base

Allowlists Are Not Spending Caps: Two Different Security Properties, Often Confused

If you've ever configured a delegated signer, a session key, or a bot's wallet permissions, you've probably reached for two knobs: an allowlist of assets it's allowed to touch, and a cap on how much…

  • Allowlists limit interactions to a predefined set of token contracts
  • Spending caps restrict the amount of value that can be moved
  • Allowlists and caps address different security failure modes

How to Start Learning Cybersecurity: A Practical Roadmap for Beginners

If you're starting cybersecurity from scratch, one of the easiest mistakes to make is beginning with Kali Linux, penetration-testing tools, or a long list of certifications. A stronger approach is to first understand the systems and networks you're trying to protect. Here is a practical learning path for beginners. 1.

  • Understand core components of computers and operating systems.
  • Familiarize with networking fundamentals like IP addresses, protocols, and models.
  • Learn core security concepts and practice hands-on Linux and Windows skills.

More from Thursday 3 September →