Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

https://www.securityweek.com/wp-content/uploads/2023/10/Zero-Day-Exploit.jpg

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia.

Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well.

In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.

The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more

https://techcrunch.com/wp-content/uploads/2024/10/matt-mullenweg.jpg?resize=1200,799

Automattic confirms Matt Mullenweg has returned to his position as chairman and CEO “with full support of the board”, after an attempted ouster this week

More: New York Times, Washington Post, BBC, The Atlantic, Axios, CoinDesk, Wall Street Journal, Wccftech, Associated Press, Washington Examiner, Semafor, Reuters, ZeroHedge News, The i Paper, Inc42, The Wrap, The Mahablog, Newser, New York Post, CNBC, Nairametrics, Joe.My.God., Fortune, TheJournal.ie, The Verge, Dexerto, Financial Times, TMZ.com,