Friday , October 2 2026
Falcon Sensor

Sleeping Beauty
Researchers Bypassed CrowdStrike Falcon Sensor partially

SEC Consult researchers found a vulnerability in CrowdStrike’s Falcon Sensor, enabling attackers to evade detection and run malicious applications. The dubbed “Sleeping Beauty” vulnerability was reported to CrowdStrike in late 2023 but was dismissed as just a “detection gap.”

The technique involved suspending the EDR processes instead of stopping them, effectively creating a window of opportunity for malicious actors to operate undetected.

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Researchers at SEC Consult discovered that an attacker with NT AUTHORITY\SYSTEM permissions on a Windows machine could use Process Explorer to suspend CrowdStrike Falcon Sensor processes.

Although the system prohibited killing these processes, it surprisingly allowed suspending them, creating a major security loophole.

Figure 2: Process Explorer allows us to Suspend or Kill a process

Process Explorer easily suspended critical security processes without any issues.

CrowdStrike’s Reaction:

SEC Consult brought the behavior to CrowdStrike’s attention via different channels, such as a HackerOne ticket (2274888) back at the end of 2023, which resulted in a closed issue and the following (shortened) statement by the vendor (vendor statement in quotes):

The vulnerability is only a “detection gap as the sensor has visibility into the action but does not generate a detect/prevent in the UI” and “suspending the user mode service does not stop the kernel components or sensor communications.

In 2025, CrowdStrike does not allow process suspension anymore and appears to have decided that process suspension is indeed a detection gap that should not exist. SEC Consult was not informed about this status update and they found out by chance during another check of CrowdStrike Falcon Sensor during another security assessments.

Vendor contact timeline:

2023-12-06: Contacting vendor through HackerOne submission (2274888)

2023-12-06: Vendor needs more info, our version seems to have been outdated, but
they could not reproduce the vulnerability.

2023-12-07: Tested latest version, sent update to vendor that it is also vulnerable.
Added further POC details for exploitation.

2023-12-07: Vendor: the vulnerability is only a “detection gap”, closes the issue.
“the sensor has visibility into the action but does not
generate a detect/prevent in the UI”, “suspending the user mode
service does not stop the kernel components or sensor
communications”.

2024-02-14: Follow-up with other vendor contacts, not via HackerOne.

2024-03-05: Asking for a status update.

2024-04-15: No updates received from any contacts.
We decided not to pursue this topic any further because of the vendor response.

2025-02: Found out that CrowdStrike FS now mitigates this issue and prepared blog post.

Click here to read the full report.

41,500+ VMware ESXi Instances Vulnerable to Attacks

Check Also

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. …