# CrowdStrike Zero-Day Exploit Released by Nightmare Eclipse

*Published September 7, 2026*
*Source: [https://thecyberwire.com/newsletters/daily-briefing/15/170](https://thecyberwire.com/newsletters/daily-briefing/15/170)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/crowdstrike-zero-day-exploit-released-by-nightmare-eclipse) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Security researcher Nightmare Eclipse has released an exploit for a zero-day vulnerability in CrowdStrike's Falcon endpoint security platform. This particular flaw is a privilege-escalation issue that targets the feature in Falcon responsible for scanning Microsoft Office documents for malicious macros. CrowdStrike has acknowledged the claims and is currently investigating the matter. In response, the company advises its customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while assuring them that protection remains intact through Cloud Anti-malware for Microsoft Office Files settings. Customers are also encouraged to consult the FalconFlank Tech Alert available in the CrowdStrike support portal.

Nightmare Eclipse is known for releasing zero-day exploits as part of a protest against Microsoft, but recent activities have expanded to include vulnerabilities in products from Kaspersky, Gen Digital, and now CrowdStrike. Security expert Kevin Beaumont has verified the functionality of these exploits, underscoring the urgency for affected organizations to take immediate protective measures.

In a separate incident, the FulcrumSec extortion group has leaked approximately 550 GB of data allegedly stolen from Manchester Airports Group after the company reportedly refused to pay a ransom. The leaked data is said to contain personal information of around 8.7 million individuals. This highlights the ongoing threat of data breaches and the extent of exposure when security measures fail.

These events underscore the need for robust security protocols and rapid response strategies to mitigate vulnerabilities and protect sensitive data.
