DAILY BRIEFING
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
Today's briefing covers an unpatched CrowdStrike LPE exploit, an exploited Chrome zero-day, widespread WordPress plugin attacks, Exchange Online email delays, and urgent updates for Plex.
5 stories2 min read

Today's news highlights significant risks across desktop systems, web infrastructure, and endpoint security agents. A zero-day exploit targeting CrowdStrike Falcon allows privilege escalation to SYSTEM status on Windows, while Google addresses an actively exploited V8 engine vulnerability in Chrome. Desktop environments and browser endpoints require immediate attention to mitigate unauthorized access.
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
A researcher going by 'Nightmare Eclipse' released 'FalconFlank', a zero-day exploit targeting CrowdStrike Falcon. The flaw allows local attackers to escalate privileges to SYSTEM on fully patched Windows machines.
- Why it matters
- Organizations relying on CrowdStrike Falcon for endpoint protection on Windows endpoints face immediate risk of complete local system compromise.
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Wordfence reports over 440,000 exploit attempts targeting arbitrary file upload vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), which allow RCE via PHP web shells.
- Why it matters
- Unauthenticated attackers can upload malicious PHP code to gain full control, execute arbitrary commands, and steal data from vulnerable WordPress sites.
- What to do
- Update Super Forms to version 6.3.314 or later and Elementor Pro to version 4.2.2 or later immediately.
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
- Why it matters
- Chrome users and enterprise fleets are exposed to browser exploits that could compromise endpoints via malicious web pages.
- What to do
- Update Google Chrome browsers immediately to the latest patched release.
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex released security patches for Plex Media Server (1.43.3) and Plex Desktop (1.115.0) addressing multiple undisclosed vulnerabilities, urging users to update manually if NAS package managers lack the build.
Exchange Online outage causes email delays, 'Server busy' errors
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains.
- Why it matters
- Organizations using Exchange Online may experience severe communication delays and disrupted email workflows with external contacts.
Key takeaways
- A researcher released the 'FalconFlank' zero-day exploit enabling local SYSTEM privilege escalation on up-to-date Windows CrowdStrike Falcon installations.
- Google patched an actively exploited high-severity zero-day vulnerability in Chrome's V8 engine alongside 11 additional security bugs.
- Threat actors launched over 440,000 exploit attempts targeting RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro…
- Plex issued updates for Plex Media Server (1.43.3) and Plex Desktop (1.115.0) to resolve multiple undisclosed security flaws.