Security Researchers Unleash Zero-Day Fury on Avast, CrowdStrike, and Nvidia
A notorious security researcher known as Nightmare Eclipse has unleashed a trio of zero-day exploits targeting some of the most prominent cybersecurity products in the industry. The exploits, dubbed PrettyPrague, FalconFlank, and GreenSection, have been discovered to affect Avast, CrowdStrike, and Nvidia’s offerings respectively.
Nightmare Eclipse, who gained notoriety for their previous exploits against Microsoft products, has now turned their attention to other vendors. In a short span of time, they released the zero-day exploits, leaving security teams scrambling to respond. The researcher claims that each exploit leverages specific vulnerabilities in the targeted products, allowing attackers to gain elevated privileges and potentially cause significant damage.
The PrettyPrague exploit specifically targets Avast’s sandbox feature, which is designed to detect and contain suspicious activity. However, Nightmare Eclipse has found a way to use this feature against the product itself, allowing an attacker to spawn a shell with full system privileges. The vulnerability may also affect other GenDigital products, including AVG and Norton.
In response to the exploit, Avast’s parent company, GenDigital, has acknowledged the issue and released a patch to address it. A spokesperson for the company emphasized the importance of keeping software up-to-date, stating that users should ensure their products are patched to prevent any potential exploitation.
The FalconFlank exploit, on the other hand, targets CrowdStrike’s Office malicious macros remediation feature. This vulnerability allows an attacker to elevate their system privileges, potentially leading to serious consequences. CrowdStrike has advised customers to disable a specific policy setting and referred them to the company’s support portal for further guidance.
Meanwhile, the GreenSection exploit affects Nvidia’s user-mode components, specifically targeting an out-of-bounds memory write in a shared global memory section. While Nightmare Eclipse notes that this vulnerability does not grant immediate SYSTEM privileges, it can be used to compromise other users’ systems or even target critical processes like dwm.exe.
Nvidia has acknowledged the reports and is actively investigating the issue. The company assures users that they take such vulnerabilities seriously and are working diligently to determine the root cause and affected configurations.
The implications of these zero-day exploits are significant, highlighting the ongoing cat-and-mouse game between security researchers and vendors. As the cybersecurity landscape continues to evolve, it’s essential for users to stay informed about potential threats and take proactive measures to protect themselves.
To mitigate such risks, it’s crucial that users keep their software up-to-date and exercise caution when interacting with potentially vulnerable systems. By staying vigilant and responsive to emerging threats, we can work together to prevent the worst-case scenarios from unfolding.
Source: SecurityWeek — 2026-09-07