← All Posts

There you have it! The software you buy to stop attackers from taking over your machine just beca…

September 6, 2026 · 0 likes · 0 comments
AI Cybersecurity
There you have it! The software you buy to stop attackers from taking over your machine just became the way attackers take over your machine.

A researcher published working exploit code — they call it FalconFlank — that turns CrowdStrike Falcon's own malicious-macro cleanup feature into a ladder from a low-privilege local account all the way up to full SYSTEM.

On fully updated Windows 11 and Windows Server 2025. Every patch installed. Falcon running in "Optimal Protection." SYSTEM anyway.

Sit with that. The guard at the door handed over the master key.

No CVE yet. No patch yet. CrowdStrike says it is "actively investigating" and tells customers to switch off one of its own protection settings in the meantime. The mitigation is: turn off part of the tool you paid to keep on.

And Falcon is not niche. It runs across more than 88,000 organizations and 62% of the Fortune 500. That is the blast radius if this gets weaponized before a fix lands.

Now the honest part, because I don't sell fear. A GitHub proof-of-concept is not a peer-reviewed disclosure, and one outlet flagged it hasn't been independently confirmed end-to-end. But Kevin Beaumont — one of the most trusted independent names in this field — says the escalations this researcher shipped this week are real and functional. This is not nothing.

And it is not one product having a bad week. The same researcher torched Kaspersky, Avast, and Nvidia in the same seven days, on top of months of Microsoft Defender zero-days. Read the pattern, not the logo.

Here is the uncomfortable engineering truth I learned running security at scale: endpoint software has to run with god-mode privileges to do its job. Those exact privileges are the prize. Every cleanup routine that touches your files is a door — and a door can be redirected.

So retire the word "secure" as a finish line. "Fully patched" is a status, not a guarantee. Your security vendor is not exempt from being the hole in the wall — sometimes it IS the hole.

Defense-in-depth was never a slogan. It is the only adult answer. Assume the tool can be turned against you, and build so that one compromised agent doesn't own the whole box.

Full briefing on Unbiased Headlines:
https://lnkd.in/exgxPBRU

If the thing guarding the vault can open the vault, what exactly are you protected from?
View original on LinkedIn →