September 8, 2026
- ConnectWise ScreenConnect has an unpatched flaw in file-transfer behaviour affecting both cloud and on-prem, with no CVE assigned and a fix promised later this week. The interim mitigation is to deselect the
TransferFiles (or legacy TransferFilesInSession) scoped permission on every role and session group. Shadowserver tracks nearly 6,000 internet-exposed instances (BleepingComputer). Separately, Huntress detailed the worm-like rogue-client activity from three unrelated August incidents: a four-stage VBScript chain (1.vbs–4.vbs) where stage one profiles RAM, checks for existing ScreenConnect installs and enumerates Cisco AMP, CrowdStrike, Huntress, Malwarebytes, SentinelOne, Sophos and Symantec into a three-bit state variable in %TEMP%\value.txt (The Hacker News, earlier coverage).
· Vulnerabilities & Exploits - Nightmare Eclipse dropped PoC exploits for CrowdStrike, Nvidia and Avast products, each yielding privilege escalation to a SYSTEM shell (SecurityWeek).
· New Tools & Releases
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 5, 2026
- FalconFlank now has a name and a vendor story: an anonymous researcher using the handle "Nightmare Eclipse" published a CrowdStrike Falcon zero-day that escalates to SYSTEM on fully patched Windows (BleepingComputer, earlier coverage). The underlying primitive isn't new — hijacking the Windows MareBackup scheduled task was documented publicly in May 2025 (SCRT). (discussion)
· Vulnerabilities & Exploitation
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
September 4, 2026
- FalconFlank, the CrowdStrike Falcon zero-day PoC teased yesterday (earlier coverage), now has a mechanism: researcher Chaotic Eclipse (MSNightmare) says it abuses the Falcon Sensor's Office malicious-macro remediation routine for local privilege escalation (The Hacker News) (discussion). Worth testing in a lab before assuming your EDR baseline is unaffected.
· New Tools & Releases
in Malware That Gaslights the AI Analyst
September 3, 2026
- A public repo claims a CrowdStrike Falcon local privilege escalation zero-day. "FalconFlank" was published with no coordinated advisory; details are limited to the repo itself, which is worth watching if you rely on Falcon as a control boundary rather than just telemetry (FalconFlank).
· Vulnerabilities & Exploitation
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
September 2, 2026
- CrowdStrike and NVIDIA built a paired attacker/defender model set and ran them against each other on a digital twin of NVIDIA's own infrastructure; both run on Nemotron, trained on Falcon telemetry and 15 years of IR data (@IntCyberDigest).
· AI & Model Security
- Sality botnet disrupted in an international takedown; CrowdStrike and law enforcement poisoned the peer-to-peer network and diverted infected hosts into sinkholes (DOJ, The Register).
· Threat Activity
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
August 2, 2026
- A full teardown of CrowdStrike Falcon maps how the sensor actually catches you. The write-up reverse-engineers the Windows sensor end to end — kernel callbacks, Windows Filtering Platform hooks, minifilter, and the detection-engine architecture — and turns up a (low-severity) bug along the way. It's a rare, detailed look at commercial EDR internals directly useful for evasion research and detection engineering alike (0xdbgman).
· Detection & Reverse Engineering
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
July 28, 2026
- NVIDIA and 37 members (including CrowdStrike, IBM, Palantir, Microsoft and Hugging Face) launched the Open Secure AI Alliance and open-sourced its NOOA framework, aimed at giving defenders open tooling to test, audit and protect models and agents (The Hacker News, SecurityWeek).
· AI & Model Security
in Agentic AI Muscles Into the Offensive Toolkit