< ciso
brief />
Tag Banner

All news with #crowdstrike tag

161 articles

AWS Client VPN adds device posture assessment

🔒 AWS Client VPN now supports device posture assessment, enabling verification that connecting user devices meet security and compliance requirements before granting access. This integrates with existing posture providers such as CrowdStrike, Jamf, and JumpCloud and uses Cedar policies for fine-grained control. A Test Policy tool helps you author and validate posture rules, and evaluations can be enforced or run in monitoring-only mode. The feature continuously re-evaluates active sessions and is available in all AWS Regions at no extra cost, requiring AWS VPN Client v6.2.0+.
read more →

SE Labs launches PIVOT test for vendor defences

🛡️ SE Labs has launched a six-month testing program called PIVOT to evaluate how effectively cybersecurity vendors defend against major nation-state and criminal threat groups. The program runs real-world attack chains from July through October in SE Labs’ London test lab and will publish verified results in January 2027. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. Gartner and Forrester analysts will independently verify the findings before publication.
read more →

Zero-day Privilege Escalation Reported in CrowdStrike

🛡️ A security researcher known as “Nightmare Eclipse” published a GitHub proof-of-concept on September 3 for a zero-day privilege escalation called FalconFlank that targets CrowdStrike Falcon Sensor. The exploit abuses the Microsoft Office file malicious macro remediation feature and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when specific CrowdStrike settings are enabled. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates and referenced a customer-only tech alert. No CVE has been assigned yet, and the researcher has also published other vendor zero-days previously.
read more →

CrowdStrike FalconFlank zero-day grants SYSTEM access

🛡️ An anonymous researcher called "Nightmare Eclipse" released a zero-day named FalconFlank that escalates privileges on fully patched Windows 11 and Windows Server systems by abusing CrowdStrike Falcon's Office malicious macros remediation. Successful exploitation spawns a command prompt with SYSTEM privileges, and CrowdStrike is investigating while advising customers to disable the Microsoft Office File Suspicious Macro Removal policy. The advisory is available to customers via the CrowdStrike support portal only.
read more →

International Operation Disrupts Long‑Running Sality Botnet

🛡️ A coordinated law enforcement action on August 31 disrupted the Sality P2P botnet, active for over 20 years. Authorities from the US, Bulgaria, Hungary and Romania, supported by Europol and private partners CrowdStrike and the Shadowserver Foundation, used sinkholing and protocol manipulation to redirect infected machines and enable remediation. The operation targeted Sality’s decentralized peer lists to remove malicious super peers and insert sinkhole entries, while ISPs and CSIRTs helped identify and notify victims.
read more →

Researcher Publishes FalconFlank PoC for CrowdStrike

🔒 A security researcher known as Chaotic Eclipse released a zero-day PoC called FalconFlank that enables local privilege escalation by abusing CrowdStrike Falcon's office malicious macros remediation. The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed, and cautions defenders may need to add exclusions or obfuscate detection to test it. This release follows recent PoCs targeting Kaspersky and Microsoft Defender, with the researcher criticizing vendor engagement.
read more →

Global takedown dismantles long-running Sality botnet

🔒 International law enforcement and private partners seized and sinkholed infrastructure tied to the Sality P2P botnet to disrupt operations and isolate infected hosts. The DOJ, FBI, and DCIS seized U.S. domains while authorities in Bulgaria, Hungary, and Romania seized European-hosted domains. CrowdStrike coordinated a peer-to-peer sinkhole that blocked Sality's super peers and payload distribution, ending operator control.
read more →

Law enforcement disrupts long‑running Sality botnet

🔒 The U.S. Department of Justice, working with international partners and industry, executed a sinkhole operation on August 31, 2026, to disrupt the Sality P2P botnet. CrowdStrike and Shadowserver collaborated with authorities from the U.S., Bulgaria, Hungary, and Romania to isolate peers and seize Sality-linked domains. The takedown prevents further payload distribution, though already infected machines still require remediation. Agencies advise reviewing network logs for beaconing to a designated sinkhole IP.
read more →

CrowdStrike unveils SafeMind agentic cybersecurity AI

🛡️ CrowdStrike introduced SafeMind, an agentic cybersecurity AI system built around two purpose-built models: the offensive Red Tempest and the defensive Blue Solano. Trained on Falcon sensor telemetry and 15 years of incident response, the models form a feedback loop where Red Tempest emulates attacks and Blue Solano learns to defend. SafeMind, built with Nvidia technology, creates a digital twin of enterprise environments and will be available natively in Falcon and via Project QuiltWorks.
read more →

NVIDIA Leads New Open Secure AI Alliance Initiative

🛡️ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more →

NVIDIA leads 37-member Open Secure AI Alliance

🔒 NVIDIA and 36 organizations have launched the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and AI agents. The group spans cloud, security, enterprise software, and AI companies including Microsoft, Cisco, CrowdStrike, Hugging Face, IBM, and the Linux Foundation. The alliance’s scope covers identity, permissions, isolation, guardrails, logs, model formats, scanning, and secure coding workflows. Its first technical contribution is NVIDIA-labs OO Agents (NOOA), an Apache 2.0 research framework to test, trace, audit, and govern agent behavior.
read more →

CrowdStrike details five novel prompt injection threats

🛡️ Security vendor CrowdStrike has added five new prompt injection techniques to its taxonomy that threaten enterprise AI deployments. These attacks manipulate LLM behavior by embedding deceptive instructions into inputs, context, or token streams to bypass safety controls and produce malicious outputs. CrowdStrike recommends threat modeling input sources, expanding testing, and enhancing detection engineering to defend against composite and multi-stage prompt attacks.
read more →

macOS XPC Flaw Lets Non‑Root Users Disable EDR/MDM

🔒 A disclosed macOS privilege escalation allows a non-root user to abuse XPC trusted caller caching to invoke privileged helper functions without authentication, impacting multiple EDR and MDM products. XM Cyber found attackers can tamper with a legitimate app to inherit its cached trust and call sensitive methods to unload or disable security agents with minimal forensic traces. Vendors including CrowdStrike and Kandji have issued fixes and mitigations, while XM Cyber released a scanner and will present findings at Black Hat.
read more →

AI-built ransomware toolkit automates EDR evasion

🛡️ A threat actor used an AI-assisted ransomware toolkit to automate Active Directory discovery and iterate EDR evasion techniques. Researchers found Cursor and Claude Opus agents used for coding, analysis, testing, and checking public research for bypass methods, with some malware tested against Sophos, CrowdStrike, and Microsoft EDR products. Sophos determined the workflow was human-directed, while AI accelerated development, producing numerous payload modules and mapping techniques to MITRE ATT&CK.
read more →

AI-assisted toolkit used to evade EDR defenses

🔍 Sophos X-Ops uncovered a lab where a threat actor used AI coding tools to develop and test malware aimed at evading EDR products. The files and Git repository showed Python scripts—many partially AI-generated—used to build and iterate evasion modules against vendors including Sophos, CrowdStrike and Microsoft. Humans retained control of the workflow, using AI to accelerate building, testing and refinement while operating inside an AI-native environment.
read more →

Researchers Disrupt Glassworm's Resilient Botnet C2

🛡️ CrowdStrike, Google, and The Shadowserver Foundation coordinated to disrupt the Glassworm botnet by simultaneously takedown of four resilient C2 channels. The threat abused Solana blockchain memo fields, the BitTorrent DHT, Google Calendar events, and traditional VPS-hosted servers to persist and evade mitigation. Active campaigns targeted developers via malicious OpenVSX and VS Code extensions and later poisoned GitHub and npm artifacts. Infected hosts now beacon to a CrowdStrike-controlled IP and YARA rules have been published to detect compromise.
read more →

Coordinated Takedown Disrupts GlassWorm C2 Channels

🛡️ CrowdStrike, together with Google and the Shadowserver Foundation, announced the simultaneous disruption of all command-and-control channels used by GlassWorm, a persistent campaign that has targeted software developers since early 2025. The operators trojanized VS Code extensions and poisoned npm and Python packages to deliver a data-theft framework capable of credential harvesting and system profiling. Multiple resilient C2 resolution layers were used — Solana memo fields, BitTorrent DHT, Google Calendar events, and commercial VPS hosts — all of which were neutralized in the coordinated action. CrowdStrike attributes the activity to likely Russia-based cybercriminals and warns about the severe risk posed by supply chain compromises to developer ecosystems.
read more →

CrowdStrike Named Leader in Gartner Cyberthreat Intelligence

🔒 CrowdStrike was named a Leader in the inaugural 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies and ranked furthest to the right for Completeness of Vision. The company emphasizes its AI-native Falcon platform and Threat AI agents — including Malware Analysis and Hunt agents — to deliver tailored, actionable intelligence at decision points. It highlights telemetry from trillions of daily events and multiple integration paths to operationalize intelligence.
read more →

CrowdStrike Launches Falcon OverWatch for Defender

🔍 CrowdStrike has introduced Falcon OverWatch for Defender, a managed threat-hunting service that brings continuous, expert-led hunting to Microsoft Defender environments without replacing existing endpoint protections. Running a lightweight Falcon sensor alongside Microsoft Defender, the offering combines human hunters, deep adversary intelligence, and AI-driven analytics to surface stealthy post‑exploit activity and escalate high-confidence threats. It promises AI-powered analysis at scale—up to 6.2 trillion events per day—broad visibility across millions of endpoints, and operationalized hunting patterns to improve detection and response across customers.
read more →

CrowdStrike Technical Risk Assessments: Exposure Patterns

🔍 CrowdStrike Professional Services' Technical Risk Assessments (TRAs) analyze hundreds of production environments annually to surface common exposure patterns, including unmanaged assets, overlooked credential paths, and the rise of shadow AI. Assessments combine external attack surface enumeration, vulnerability and identity hygiene reviews, and hands-on validation to produce prioritized remediation recommendations. Findings stress that having the right tools is insufficient without operational discipline, clear ownership, and continuous validation to reduce breach likelihood.
read more →