Skip to main content
Security

CrowdStrike investigates Falcon privilege-escalation zero-day

CrowdStrike investigates Falcon privilege-escalation zero-day Image: Primary
CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform. The exploit is said to abuse Falcon's Office malicious-macros remediation feature. CrowdStrike advised customers to disable the related Microsoft Office File Suspicious Macro Removal policy while retaining Cloud Anti-malware for Microsoft Office Files settings. The flaw has no CVE identifier, but an independent security expert confirmed the released privilege-escalation exploits work.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Microsoft reports spike in Unicode-tag spam obfuscation

Microsoft reported a sharp rise this year in spam using invisible Unicode tag characters to obscure keywords from email filters. Its Defender for Office signatures rose from about 21,000 a day to more than 1.3 million on one day ...

Security
Security

Microsoft flags Unicode-smuggling phishing campaign

Microsoft is alerting customers to a high-volume phishing campaign that used invisible Unicode tag characters to split financial-lure words and evade literal email-filter matching. The company said the activity began in early Febr...

Policy Security
Policy Security

US military disables ad tracking on government-issued devices

Defense Department components disabled advertising tracking on government-issued iPhones, Android devices and Windows computers, according to a letter shared with Sen. Ron Wyden. The Army, Air Force, Navy, Marine Corps and Special...

Security
Security

Rapid7 links HAProxy backdoor toolkit to North Korean actors

Rapid7 Labs found a previously undocumented Linux toolkit compiled into trojanized HAProxy load balancers at two South Korean organizations. The implant, called ted in debug strings, intercepted traffic and could serve altered pag...

Security
Security

Trezor says ShipMonk breach exposed data on 67,000 more US customers

Trezor said a breach at shipping provider ShipMonk exposed personal information for about 67,000 additional US customers, expanding an incident first disclosed in August. The newly identified records concern orders processed from...