Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Macron to hold first talks with UK’s Burnham after viewing Bayeux Tapestry in London

    September 3, 2026

    How Merkel and Merz lost eastern Germany to the AfD – POLITICO

    September 3, 2026

    MoD withheld information about nuclear test veterans’ records, ex-minister claims

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Macron to hold first talks with UK’s Burnham after viewing Bayeux Tapestry in London
    • How Merkel and Merz lost eastern Germany to the AfD – POLITICO
    • MoD withheld information about nuclear test veterans’ records, ex-minister claims
    • Hands-on with Philips Hue’s new Liane 360° Rope Lights
    • Perplexity Open Sources Lily: A Rust + Metal Inference Engine for Qwen3.6-35B-A3B on Apple Silicon
    • Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
    • Thailand puts private wallets and offshore crypto transfers on notice in a major new crypto rule
    • Ontology forces urgent node upgrade after restarting chain hit by malicious activity
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 03, 2026Vulnerability / Endpoint Security

    The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon.

    “FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now.

    “So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.”

    The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon. The Hacker News has contacted CrowdStrike for comment, and we will update the story if we hear back.

    Cybersecurity

    The development comes days after Chaotic Eclipse released a PoC for another privilege escalation flaw impacting Kaspersky’s endpoint security product for Windows (version 14.0.0.504). The exploit has been codenamed HardBreacher.

    “The PoC is not in the best shape at all, it is basically duct tapped, I just managed to make it work and that’s all,” the researcher said. “It will fail to run with error so you just have to keep rerunning it. If it succeeds, it will create a file in C:WindowsSystem32MY_SNAKE_IS_SOLID.dll with full permissions for the current user.”

    “The interesting part about this is that Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files it’s not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess.”

    Last month, the researcher also published a PoC for a Microsoft Defender zero-day called ShieldBreak (aka CVE-2026-69414) that could grant an attacker the ability to run arbitrary code with NT AUTHORITYSYSTEM privileges. It’s assessed to be a patch bypass for CVE-2026-50656 (aka RoguePlanet). Microsoft has yet to release a fix.

    “Like its predecessors, ShieldBreak explores a different corner of the Windows operating system,” LevelBlue said. “Where RedSun abused the Cloud Files API and TieringEngineService to redirect a Defender write into System32, and LegacyHive weaponized offline registry hive manipulation and the NT Object Manager namespace, ShieldBreak combines Cloud Files, Object Manager namespace manipulation, direct Windows Defender API invocation, and a timing race in the remediation path.”

    Cybersecurity

    “The result is a self-contained local privilege escalation chain in which Windows Defender’s own clean engine is redirected to write an attacker-supplied DLL to C:WindowsSystem32phoneinfo.dll, followed by SYSTEM execution through the built-in Windows Error Reporting task.”

    Shortly after, the researcher claimed that Microsoft continues to ghost them and refuses to engage in “any sort of communication,” stating the company is “trying hard to paint me as some insane criminal.”

    “I can’t even report the bugs I find to their respective vendors because of the restrictions by Microsoft, all of this is of their own doing and you know, they don’t even bother to check my case to figure out what’s wrong,” they said in a post dated August 14, 2026.

    “Think I will start publishing bugs for third-parties in that window where patch Tuesday isn’t released yet. I just want to live like a normal human being for once in my life, is that too much to ask for…?”

    CrowdStrike Escalation Falcon FalconFlank PoC Privilege Releases Researcher showing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    US charges Russian for infecting 80,000 freelancers with malware

    23-Year-Old Sality P2P Botnet Disrupted

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Macron to hold first talks with UK’s Burnham after viewing Bayeux Tapestry in London

    September 3, 2026

    How Merkel and Merz lost eastern Germany to the AfD – POLITICO

    September 3, 2026

    MoD withheld information about nuclear test veterans’ records, ex-minister claims

    September 3, 2026

    Hands-on with Philips Hue’s new Liane 360° Rope Lights

    September 3, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Macron to hold first talks with UK’s Burnham after viewing Bayeux Tapestry in London

    September 3, 2026

    How Merkel and Merz lost eastern Germany to the AfD – POLITICO

    September 3, 2026

    MoD withheld information about nuclear test veterans’ records, ex-minister claims

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.