Close Menu
Edu Expertise Hub
    Facebook X (Twitter) Instagram
    Saturday, July 5
    • About us
    • Contact
    • Submit Coupon
    Facebook X (Twitter) Instagram YouTube
    Edu Expertise Hub
    • Home
    • Udemy Coupons
    • Best Online Courses and Software Tools
      • Business & Investment
      • Computers & Internet
      • eBusiness and eMarketing
    • Reviews
    • Jobs
    • Latest News
    • Blog
    • Videos
    Edu Expertise Hub
    Home » Latest News » CrowdStrike apologises to US government for global mega-outage
    Latest News

    CrowdStrike apologises to US government for global mega-outage

    TeamBy TeamSeptember 26, 2024No Comments6 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    CrowdStrike apologises to US government for global mega-outage
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A senior CrowdStrike executive has apologised in front of a United States government committee for the 19 July outage that caused IT systems around the world to crash and display the feared blue-screen-of-death after the company pushed a faulty update live.

    The incident, which took place in the early morning in the UK, began when CrowdStrike issued an update to its Falcon threat detection platform but due to a bug in its automated content validator tool, the template containing “problematic” content data was cleared for deployment.

    This in turn led to an out-of-bound memory condition which caused Windows computers receiving the update to enter a boot loop. This means affected devices restarted without warning during the startup process leaving them unable to finish a complete boot cycle.

    The resulting chaos crippled 8.5 million computers for a brief period of time and affected organisations across the globe, with the impacts particularly keenly felt in the transport and aviation sectors.

    In opening remarks before the House Committee on Homeland Security in Washington DC, Adam Meyers, CrowdStrike senior vice president for counter adversary operations, said that the organisation let its customers down when it pushed the faulty update.

    “On behalf of everyone at CrowdStrike, I want to apologise. We are deeply sorry this happened and are determined to prevent it from happening again,” said Meyers.

    “We appreciate the incredible round-the-clock efforts of our customers and partners who, working alongside our teams, mobilised immediately to restore systems and bring many back online within hours. I can assure you that we continue to approach this with a great sense of urgency.”

    He continued: “More broadly, I want to underscore that this was not a cyber attack from foreign threat actors. The incident was caused by a CrowdStrike rapid response content update. We have taken steps to help ensure that this issue cannot recur, and we are pleased to report that, as of 29 July, approximately 99% of Windows sensors were back online.

    “Since this happened, we have endeavoured to be transparent and committed to learning from what took place,” said Meyers. “We have undertaken a full review of our systems and begun implementing plans to bolster our content update procedures so that we emerge from this experience as a stronger company. I can assure you that we will take the lessons learned from this incident and use them to inform our work as we improve for the future.”

    Andrew Garbarino, member and chair of the Subcommittee on Cyber Security and Infrastructure Protection, said: “The sheer scale of this error was alarming. If a routine update could cause this level of disruption, just imagine what a skilled, determined, nation state actor could do.

    “We cannot lose sight of how this incident factors into the broader threat environment,” he said. “Without question, our adversaries have assessed our response, recovery and true level of resilience.

    “However, our enemies are not just nation states with advanced cyber capabilities – they include a range of malicious cyber actors who often thrive in the uncertainty and confusion that arise[s] during large-scale IT outages,” said Garbarino.

    “CISA [the US Cybersecurity and Infrastructure Security Agency] issued a public statement noting that it had observed threat actors taking advantage of this incident for phishing and other malicious activity. It is clear that this outage created an advantageous environment ripe for exploitation by malicious cyber actors.”

    Disruptions caused

    Committee chair Mark Green highlighted the disruption to flights, emergency services and medical procedures, not just in the US but around the world. “A global IT outage that impacts every sector of the economy is a catastrophe that we would expect to see in a movie,” he said. “It’s something that we would expect to be carefully executed by malicious and sophisticated nation-state actors.

    “To add insult to injury, the largest IT outage in history was due to a mistake,” said Green. “In this case, CrowdStrike’s content validator used for its Falcon sensor did not catch a bug in a channel file. It also appears that the update may not have been appropriately tested before being pushed out to the most sensitive part of a computer’s operating system. Mistakes happen, however we cannot allow a mistake of this magnitude to happen again.”

    During his testimony, Meyers also set out details of the precise nature of the problem, and outlined the steps CrowdStrike has taken to ensure it cannot happen again, although he revealed little information that has not already been made public.

    He faced close to an hour and a half of questions from US politicians, including a grilling on what support CrowdStrike provided to operators of critical national infrastructure (CNI) affected by the outage, and its own observation of the exploitation of the downtime by cyber criminals.

    Kernel access

    Importantly, Meyers defended the need for CrowdStrike to have access to the Microsoft kernel, a core part of the Microsoft Windows operating system, which manages various resources and processes on the system and often hosts critical cyber security applications, including the Falcon endpoint detection and response sensor.

    In the wake of the incident, some have claimed that for Microsoft to permit such access is dangerous, and a better practice would be to deploy such updates directly to users.

    “CrowdStrike is one of the many vendors out there that uses the Windows kernel architecture – which is an open kernel architecture, a decision that was made by Microsoft to enable the operating system to support a vast array of different types of hardware and different systems,” said Meyers.

    “The kernel is responsible for the key areas where you can ensure performance, where you can have visibility into everything happening on that operating system, where you can provide enforcement – in other words, threat prevention – and to ensure anti-tampering, which is a key concern from a cyber security perspective,” he said. “Anti-tampering is very concerning because when a threat actor gains access to a system, they would seek to disable security tools, and in order to identify that that’s happening, kernel visibility is required.

    “The kernel driver is a key component of every security product that I can think of,” added Meyers. “Whether they do most of their work in the kernel or not varies from vendor to vendor, but to try to secure the operating system without kernel access would be very difficult.”

    This post is exclusively published on eduexpertisehub.com

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Team

      Related Posts

      From the FBI to F&A: lessons learnt in safeguarding systems and data

      July 5, 2025

      Supreme Court Ruling Highlights Continued Power Struggle Over LGBTQ+ Books in Schools

      July 5, 2025

      10 (and counting…) Google goodies for your classroom

      July 4, 2025

      Air France-KLM to increase intelligence of bots that have saved 200,000 hours

      July 4, 2025

      Large Public Libraries Give Young Adults Across U.S. Access to Banned Books

      July 3, 2025

      5 strategies to get your students talking

      July 3, 2025
      Courses and Software Tools

      Extreme Privacy: What It Takes to Disappear

      August 24, 202454 Views

      Modern C++ Programming Cookbook: Master Modern C++ with comprehensive solutions for C++23 and all previous standards

      September 18, 202427 Views

      Meebook E-Reader M7 | 6.8′ Eink Carta Screen | 300PPI Smart Light | Android 11 | Ouad Core Processor | Out Speaker | Support Google Play Store | 3GB+32GB Storage | Micro-SD Slot | Gray

      August 19, 202422 Views

      HR from the Outside In: Six Competencies for the Future of Human Resources

      May 20, 202517 Views

      Coders at Work: Reflections on the Craft of Programming

      April 19, 202516 Views
      Reviews

      Senior Scientist II, Chemistry

      July 5, 2025

      Fundraising For Creators With Cryptocurrency Crowdfunding | Udemy Coupons 2025

      July 5, 2025

      Software Development Engineer – FBDA, Fire TV Channels, FBDA Video Ads

      July 5, 2025

      C# 12 and .NET 8 – Modern Cross-Platform Development Fundamentals: Start building websites and services with ASP.NET Core 8, Blazor, and EF Core 8

      July 5, 2025

      Options Trading Simplified For Beginners: Master The Essential Options Skills For Generational Wealth Even With A Small Account

      July 5, 2025
      Stay In Touch
      • Facebook
      • YouTube
      • TikTok
      • WhatsApp
      • Twitter
      • Instagram
      Latest News

      From the FBI to F&A: lessons learnt in safeguarding systems and data

      July 5, 2025

      Supreme Court Ruling Highlights Continued Power Struggle Over LGBTQ+ Books in Schools

      July 5, 2025

      10 (and counting…) Google goodies for your classroom

      July 4, 2025

      Air France-KLM to increase intelligence of bots that have saved 200,000 hours

      July 4, 2025

      Large Public Libraries Give Young Adults Across U.S. Access to Banned Books

      July 3, 2025
      Latest Videos

      What is Digital Marketing? Scope, Earnings & Who Can Start a Career in It Hammad’s Digital Hub

      July 5, 2025

      Just trend #gacha #memecreator #gachaclub #gcmeme #gachalife #trend #gachememe #edit #memes

      July 4, 2025

      Kenley Jansen notches his 1,000th career MLB strikeout | August 25, 2021 | Dodgers @ Padres

      July 3, 2025

      Top 5 Cyber Security Jobs in India || Cyber Security Career 2024

      July 2, 2025

      Navigate Your Marketing Career with Expert Mentorship | NIMS Academy Success Guide

      July 1, 2025
      Latest Jobs

      Senior Scientist II, Chemistry

      July 5, 2025

      Software Development Engineer – FBDA, Fire TV Channels, FBDA Video Ads

      July 5, 2025

      Youth Programs – Dance Class Instructor

      July 5, 2025

      Part Time Educator (South River, NJ)

      July 5, 2025

      Occupational Therapist – Full, Part Time & PRN Skilled Nursing Community

      July 5, 2025
      Legal
      • Home
      • Privacy Policy
      • Cookie Policy
      • Terms and Conditions
      • Disclaimer
      • Affiliate Disclosure
      • Amazon Affiliate Disclaimer
      Latest Udemy Coupons

      Mastering Maxon Cinema 4D 2024: Complete Tutorial Series | Udemy Coupons 2025

      August 22, 202435 Views

      Advanced Program in Human Resources Management | Udemy Coupons 2025

      April 5, 202531 Views

      Diploma in Aviation, Airlines, Air Transportation & Airports | Udemy Coupons 2025

      March 21, 202530 Views

      Python Development & Data Science: Variables and Data Types | Udemy Coupons 2025

      May 24, 202521 Views

      Time Management and Timeboxing in Business, Projects, Agile | Udemy Coupons 2025

      April 2, 202521 Views
      Blog

      3 Ways To Network Over Summer Vacation And Grow Your Career

      July 3, 2025

      Why Community Is Your Most Valuable Career Asset In 2025

      June 28, 2025

      What Employers Are Really Looking For In Job Interviews

      June 27, 2025

      The Best Way to End a Cover Letter (With 4 Winning Examples)

      June 26, 2025

      5 Job Interview Secrets To Beat The Competition

      June 25, 2025
      Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
      © 2025 All rights reserved!

      Type above and press Enter to search. Press Esc to cancel.

      We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
      .
      SettingsAccept
      Privacy & Cookies Policy

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
      Non-necessary
      Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
      SAVE & ACCEPT