<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Exploit on Blog - Comfidentia</title><link>https://blog.comfidentia.cl/en/tags/exploit/</link><description>Recent content in Exploit on Blog - Comfidentia</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.comfidentia.cl/en/tags/exploit/index.xml" rel="self" type="application/rss+xml"/><item><title>Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank</title><link>https://blog.comfidentia.cl/en/2026/09/03/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.comfidentia.cl/en/2026/09/03/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank/</guid><description>&lt;h2 id="chaotic-eclipse-unveils-falconflank-zero-day-for-crowdstrike-falcon"&gt;Chaotic Eclipse Unveils FalconFlank Zero-Day for Crowdstrike Falcon&lt;/h2&gt;
&lt;p&gt;Security researcher Chaotic Eclipse, also known by aliases like INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, has publicly released &amp;ldquo;FalconFlank,&amp;rdquo; a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability affecting the Crowdstrike Falcon cybersecurity platform.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/br&gt;&lt;/p&gt;
&lt;h3 id="details-of-falconflank-exploit"&gt;Details of FalconFlank Exploit&lt;/h3&gt;
&lt;p&gt;FalconFlank exploits Falcon&amp;rsquo;s &amp;ldquo;Microsoft Office file malicious macro removal&amp;rdquo; feature. This remediation function, which operates with high privileges, can be abused to escalate privileges from a low-privileged local user to a more powerful system context.&lt;/p&gt;</description></item></channel></rss>