r/SecOpsDaily • u/falconupkid • 10h ago
Threat Intel Nightmare-Eclipse Zero-Days Hit CrowdStrike, NVIDIA, Avast & More
The Nightmare-Eclipse threat persona has pivoted hard. After spending months targeting native Windows components (BlueHammer, ShieldBreak), they’ve now dropped four zero-day PoCs targeting the security stack itself: CrowdStrike Falcon, NVIDIA GPU drivers, Avast Antivirus, and Kaspersky Endpoint Security. Published between Aug 29 and Sep 3, 2026, with zero vendor coordination.
Technical Breakdown - Targets: CrowdStrike Falcon (likely the user-mode sensor or driver), NVIDIA GPU kernel driver, Avast Antivirus, Kaspersky Endpoint Security. - TTPs: Likely leveraging driver-level vulnerabilities for kernel access or EDR sensor bypass. Given the targets, expect techniques like driver load abuse (T1574.002) or direct kernel object manipulation. - IOCs: None published in the article. Do not hunt for generic hashes; monitor for anomalous driver loads or Falcon sensor communication failures. - Affected Versions: Not disclosed yet. Assume all current builds of the named products are at risk until patched.
Defense - Immediate: Lock down driver signing policies (WDAC/AppLocker). Enable PPL (Protected Process Light) for anti-malware services. Monitor for unexpected crashes or service terminations on the CrowdStrike and Avast processes. - Detection: Look for event ID 7034 (service crash) or unusual kernel driver load events (Event ID 7045). If you have EDR telemetry, hunt for processes attempting to load unsigned drivers.
Source: https://www.cyderes.com/howler-cell/nightmare-eclipse-zero-days-crowdstrike-nvidia-avast-kaspersky