The record
Written from the 1 report below. Nothing here is unsourced.
- A researcher known as Chaotic Eclipse has publicly released a proof-of-concept for a zero-day privilege escalation flaw in CrowdStrike Falcon Sensor, dubbed FalconFlank, which abuses the product's malicious macro remediation feature on fully updated Windows systems.
- The disclosure follows similar recent releases by the same researcher, including HardBreacher affecting Kaspersky's endpoint security product, which the company says it has fixed via automatic updates, and ShieldBreak (CVE-2026-69414) affecting Microsoft Defender, for which no fix exists yet.
- The researcher claims Microsoft refuses to communicate with them, prompting threats to publish more bugs without coordinated disclosure.
- These unpatched flaws could let attackers gain elevated privileges on systems running these widely used security products, and vendors are under pressure to respond.
What to watch next
- Whether CrowdStrike responds to The Hacker News' request for comment and releases a fix or detection for FalconFlank.
- Whether Microsoft patches ShieldBreak (CVE-2026-69414) in an upcoming Patch Tuesday release.
- Whether the researcher follows through on publishing more third-party bugs between Patch Tuesday cycles.
Coverage1
1 report
English national1
All filed from India
Named India · CrowdStrike · Kaspersky · Microsoft · Chaotic Eclipse
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
