July 19, 2024 was a black day for the Web. The trend of the day was “Microsoft down”, but i Global disruptions that have caused chaos across multiple industries were caused by CrowdStrike, a leading cybersecurity company.
The company is known for its endpoint protection platform, Falcon. However, a problematic update to its software caused Windows PCs using it to crash, interrupting services for many customers.
The incident caused CrowdStrike shares to drop 20% in pre-market trading and fall about 10% in regular trading. But who is Crowdstrike and what exactly does it do?
Who is CrowdStrike?
Founded in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston, CrowdStrike has quickly established itself as a leader in the cybersecurity field. The company's mission is provide advanced cybersecurity solutions, using artificial intelligence and machine learning technologies to proactively prevent cyber attacks.
CrowdStrike's main platform, Falcon, is a suite of solutions from cloud-based security. Using lightweight sensors installed on endpoints, Falcon collects data that is centrally analyzed to identify and neutralize threats in real time.
Le main features of the platform include:
- Endpoint Detection and Response (EDR): Provides real-time visibility and rapid response capabilities to advanced threats.
- Threat Intelligence: Analyzes the global threat landscape and provides updates on new attacks and techniques used by attackers.
- Incident Response: Helps organizations manage and mitigate the consequences of a security breach.
- Managed Threat Hunting: Continuous monitoring of endpoints by security experts to identify and neutralize potential threats.
- Cloud Security: Protection of cloud resources, including workloads and applications on cloud platforms.
CrowStrike IT Failure: What Happened?
Therefore, the cyber failure that crippled numerous systems globally was not caused by a cyberattack, but by a technical problem of the software.
Il malfunctions was triggered by a buggy update of CrowdStrike's Falcon Sensor software, designed for Windows hosts. This update caused the operating system to crash, with numerous computers displaying the infamous Blue Screen of Death (BSoD).
I sectors affected were large and varied, including banks, media and airlines, resulting in disruptions to daily operations. Company computers that received the problematic update failed to reboot properly, effectively halting business operations.
CrowdStrike promptly recognized the problem and proceeded tocanceling the update globally. In a statement, the company confirmed that it was aware of the crashes on Windows hosts and said it was working to resolve the situation. George Kurtz, CEO of CrowdStrike, reassured that the flaw has been identified and fixed, and that the company's team is fully mobilized to ensure the safety and stability of customers.
Meanwhile, for companies that couldn't wait for a complete solution from CrowdStrike, one was suggested temporary procedure for recovering computers. Kurtz stressed that Mac and Linux hosts were not affected and clarified that this is a technical issue, not a security incident or cyberattack.
CrowdStrike: looking for the solution
CrowdStrike is still committed to solving the problem. The company immediately took action to release a fix and advised customers to use the support portal for the latest news and communicate through official channels to ensure safe management of fixes.
Despite having identified the problem and reverted the service to an earlier version, CrowdStrike has warned that affected computers may be affected. manual intervention is required beyond simply rebooting. Experts suggest use a previous backup update if available, or boot your computers in safe mode and manually remove the problematic file called “C-00000291.sys”. After this operation, computers should boot correctly.
But there is also the risk that to completely solve the problem they can spend several days. CrowdStrike has provided a temporary solution which involves manual removal of the offending file, but in some cases physical intervention on the devices will be necessary, especially for companies with numerous computers or those equipped with encryption systems. This “workaround” is a temporary measure pending an automatic remote update, but should still ensure adequate protection against further attacks.
