Find notable cyber news and cases, enriched with sources, timelines, and signals.

CrowdStrike Falcon Sensor privilege escalation zero-day FalconFlank privilege-escalation flaw

Vulnerability
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

FalconFlank is a publicly released zero-day privilege escalation in CrowdStrike Falcon Sensor that can give attackers SYSTEM access on fully updated Windows 11 and Windows Server 2025 systems. The flaw abuses Falcon's Office malicious macros remediation feature and is described as working on current builds, including Windows 11 25H2. CrowdStrike says it is investigating and advises customers to disable the File Suspicious Macro Removal policy setting while it reviews the claim.

Related Happenings

Steam discussion forums ClickFix campaign deploying XMRig miners

Campaign
H score34 First: 26.07.2026 01:37 Last: 26.07.2026 01:37 Sources 1

About this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...

Latest development: 03.09.2026 13:43

KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

Windows cldflt.sys privilege escalation (CVE-2020-17103)

Vulnerability
H score28 First: 18.05.2026 01:30 Last: 18.05.2026 01:30 Sources 1

About this happening: A public MiniPlasma proof-of-concept has renewed concern around the Windows cldflt.sys Cloud Filter driver because it can elevate a standard user to SYSTEM on fu...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Timeline

  1. 04.09.2026 16:22 2 articles · 15h ago

    Nightmare Eclipse releases FalconFlank zero-day for CrowdStrike Falcon

    Initial Disclosure

    An anonymous researcher using the Nightmare Eclipse handle publicly released FalconFlank, a CrowdStrike Falcon zero-day that can escalate privileges to SYSTEM on up-to-date Windows 11 and Windows Server systems by abusing Falcon Sensor's Office malicious macros remediation feature; the researcher said it works on fully updated Windows 11 25H2 and Windows Server 2025, and CrowdStrike said it is actively investigating the claims while advising customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting and pointing customers to a FalconFlank Tech Alert in its support portal.

    Show sources