Search
Find merged stories by title or summary.
Happy Birthday, Shai-Hulud
This week marks one year since an attacker pushed a malicious version of @ctrl/tinycolor to npm, kicking off the worst year for npm security on record. At the time, the package was downloaded more than two million times a week. Within a day the same code was spreading on its own across dozens of packages, and then into CrowdStrike's npm namespace . It was the first known self-propagating worm in the npm ecosystem, and it has not really stopped since. The tinycolor compromise put software supply chain security on everyone's radar in a way it had not been before. Teams that had never given much thought to what they were installing from npm suddenly started paying attention. The worm harvested credentials and republished itself # The payload was a bundle. js file that ran TruffleHog, a legitimate secret scanner, to sweep the host for npm tokens, GitHub credentials, and cloud keys.
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
CrowdStrike SafeMind Uses the Best Offense to Build the Best Defense
Salt Security expands CrowdStrike integration to tackle AI agent security
Salt Security has expanded its integration with CrowdStrike to give security teams greater visibility into how AI agents connect to enterprise systems, use APIs and exercise their permissions. The expanded partnership brings together Salt’s Agentic API platform with CrowdStrike Falcon Foundry , Falcon Next-Gen SIEM and Falcon Firewall Management . According to the companies, the integration is designed to help joint customers discover AI agents operating across their environments and track the infrastructure and permissions that allow them to act. The move comes as enterprises shift from experimenting with generative AI towards deploying agents capable of performing tasks autonomously. These agents can hold credentials, connect to internal systems through Model Context Protocol (MCP) servers and tools, invoke APIs and take actions on behalf of employees.
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter - Hackread
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter Hackread
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
Why AI raises the stakes for exposure validation
AI dominated the conversation at Fal. Con 2026, but one of the most important takeaways wasn’t simply how AI is changing cyber defense. It was how AI is changing the speed and scale of a problem defenders already face. Security teams already have more vulnerabilities and security signals than they can reasonably act on. As AI makes it faster to discover vulnerabilities and determine whether they can be exploited, finding more weaknesses only makes one question more important: Which exposures actually matter in my environment? That question surfaced throughout Fal. Con. In his keynote, CrowdStrike CEO George Kurtz spoke about AI as the new cyber battlefield, offense informing defense, AI red teaming, and the need for a continuous approach to security. For defenders, that means moving beyond theoretical risk to understand what attackers can exploit in their specific environments.
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
Mars Security Debuts Automated Threat Engine Processing Live Cyber Intelligence Into Validated Rules Within Minutes
Mars Security , an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published threat intelligence advisories into production-ready, validated detection rules within minutes of release. Developed by former military red team operators, the capability systematically ingests threat reports from organizations such as CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence. The platform translates raw indicators and adversary techniques into native, MITRE ATT&CK-mapped detection logic across an enterprise’s active security infrastructure—including CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, and data lakes like Snowflake and Databricks.
Mars Security brings threat intelligence to detection in real time
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live. Mars believes it is the first platform … More → The post Mars Security brings threat intelligence to detection in real time appeared first on Help Net Security .
8 Antivirus (Endpoint Protection) Software for Business: Our Top Picks by Use Case (2026)
Bottom line up front: if you hold Microsoft 365 E5, you already own enterprise-grade endpoint protection and should start there. If you have no security specialist, Sophos is the platform you’ll actually operate. If you have a SOC and the budget to use it, CrowdStrike. Everything else is a fit question. Business endpoint protection prevents, detects, and responds to malware and attacks on laptops, desktops, and servers combining signature matching, behavioural analysis, machine learning, and exploit prevention in one centrally managed agent. Stage 1 — Size Yourself Honestly The single most useful thing you can do before evaluating anything is work out which of th ese you are.
Top 10 Best Managed Detection & Response (MDR) Services in 2026
MDR gives you a 24/7 security operations team without hiring one. Modern Managed Detection and Response (MDR) services fuse advanced analytics with continuous human oversight to contain intrusions across distributed environments. CrowdStrike Falcon Complete scores highest on detection and response authority, Expel leads on transparency, and Huntress delivers the best value for small businesses and the MSPs who serve them. But the single most important variable in this category isn’t detection quality it’s what the provider is contractually allowed to do at 3 a. m. without waking you up. Here are the ten best, scored, plus two consolidation facts that affect this list directly. The 2026 MDR Scorecard Rank Provider Detection quality (25%) Response authority (25%) Transparency (20%) Coverage breadth (15%) Value (15%) Total 1 CrowdStrike Falcon Complete 10 10 8 8 6 8.
Top 10 Best Extended Detection & Response (XDR) Platforms in 2026
Palo Alto Cortex XDR scores highest in our 2026 evaluation, with CrowdStrike close behind on detection engineering and Microsoft Defender XDR leading on economics for organizations already holding E5. Modern Extended Detection and Response (XDR) solutions correlates signals from endpoints, network, email, identity, and cloud into single investigable incidents reducing alert volume rather than adding another console. Here are the ten best, scored, and the one architectural question that should decide your shortlist. The 2026 XDR Scorecard Rank Platform Data coverage (25%) Correlation quality (25%) Response automation (20%) Openness (15%) Operability (15%) Total 1 Palo Alto Cortex XDR 10 10 9 6 7 8. 8 2 CrowdStrike 9 9 9 7 8 8. 5 3 Microsoft Defender XDR 9 9 8 5 8 8. 2 4 SentinelOne Singularity 8 8 10 8 8 8. 3 5 Trend Micro Vision One 9 8 7 7 7 7. 9 6 Trellix 8 8 7 7 6 7.
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek .
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges
CrowdStrike Launches SafeMind Frontier Cybersecurity Models Built With NVIDIA Nemotron
CrowdStrike has launched SafeMind, a family of purpose-built cybersecurity models and agentic AI harnesses designed to help defenders identify, validate, and remediate threats inside the Falcon platform. Announced during Fal.Con 2026 in Las Vegas, SafeMind represents CrowdStrike’s move away from relying solely on general-purpose frontier models for security operations. The company said the new system was created specifically for cyber defense, combining offensive simulation, defensive response, and continuous model improvement within a closed-loop architecture. CrowdStrike Launches SafeMind Frontier Cybersecurity Models Developed by CrowdStrike’s newly created Cyber Superintelligence Lab, SafeMind is an agentic system that acts on security findings rather than simply producing alerts, summaries, or recommendations.
Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router compromises, emerging autonomous AI attack vectors, and major cloud identity incidents. Below are detailed summaries of the top developments impacting enterprise defense and threat landscapes this week. CrowdStrike Falcon Sensor Privilege Escalation Claim A security researcher operating under the alias Nightmare-Eclipse published a proof-of-concept exploit named FalconFlank targeting the CrowdStrike Falcon Sensor. The project alleges an unverified local privilege escalation vulnerability affecting Windows 11 and Windows Server 2025 systems running Phase 3 Optimal Protection. According to the researcher, the exploit abuses the sensor’s remediation workflow when removing malicious Microsoft Office macros.
CrowdStrike Launches SafeMind – First Agentic Cybersecurity Solution Built for Defenders
CrowdStrike has unveiled SafeMind, a family of purpose-built security models and harnesses that the company is calling the first agentic system engineered specifically for cyber defenders. Announced at Fal.Con 2026 in Las Vegas, the launch marks a strategic pivot away from generic frontier AI models toward a dedicated offensive-defensive framework built to operate natively inside the CrowdStrike Falcon platform. The system emerges from CrowdStrike’s newly established Cyber Superintelligence Lab and represents one of the most ambitious applications of agentic AI in enterprise security to date. CrowdStrike Launches SafeMind What sets SafeMind apart from conventional large language model deployments is its dual-model design.
FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor
CyberKendra reports: A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE — published working exploit code to GitHub on September 3, 2026, without giving CrowdStrike advance notice. No CVE ID… Source https://databreaches.net/2026/09/05/falconflank-zero-day-hits-crowdstrike-falcon-sensor/1post-1participantReadfulltopic
What the Flock?
The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode?
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [... ]
FalconFlank PoC Claims CrowdStrike Falcon Zero-Day Enables Privilege Escalation on Windows
A proof-of-concept (PoC) dubbed FalconFlank claims to exploit a previously undisclosed privilege-escalation issue in the CrowdStrike Falcon Sensor for Windows . The alleged flaw is said to abuse Falcon’s remediation workflow for malicious Microsoft Office macros, potentially allowing a lower-privileged user to gain elevated access on fully patched Windows endpoints. According to MSNightmare, FalconFlank affects devices running CrowdStrike Falcon with “Microsoft Office file malicious macro removal” enabled. FalconFlank PoC Claims CrowdStrike Falcon Zero-Day The researcher claims successful testing against fully updated Windows 11 25H2 and Windows Server 2025 systems configured with CrowdStrike Falcon’s Phase 3 Optimal Protection policy.
CrowdStrike Disrupts Sality Botnet After More Than 20 Years - TechRepublic
CrowdStrike Disrupts Sality Botnet After More Than 20 Years TechRepublic
Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank
Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse , also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw. According to the researcher, FalconFlank abuses Falcon’s “Microsoft Office file malicious macro removal” feature. The function is part of Falcon’s remediation capabilities and operates with high privileges. The researcher claims that this behavior can be abused to escalate privileges from a low-privileged local user to a more powerful context.
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding
Dogged Russia-based botnet dismantled after 23-year run
Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation. CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable. The peer-to-peer botnet was a persistent piece of criminal infrastructure that evaded disruption for an exceptionally long period because it lacked centralized architecture. Sality used infected machines to communicate peer-to-peer, creating a decentralized structure that made system-wide disruption efforts more difficult than botnets that rely on a core server.
CrowdStrike Announces Agentic Identity Provider
CrowdStrike Announces Agentic Identity Provider
CrowdStrike Delivers the Next Evolution of the Agentic SOC
CrowdStrike Delivers the Next Evolution of the Agentic SOC
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
CrowdStrike Extends Endpoint Security to Stop Supply Chain Attacks
FBI and CrowdStrike Disrupt 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems
The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims worldwide since 2003. The operation spanned the United States, Bulgaria, Hungary, and Romania, bringing together federal law enforcement and private-sector cybersecurity firms to dismantle infrastructure that had quietly powered cryptocurrency theft and cyberattacks for more than two decades. FBI and CrowdStrike Disrupt Sality Botnet After 20 Years Key to the disruption, as confirmed by the U. S. Department of Justice announcement , was the close cooperation between the DOJ, FBI, the Department of Defense’s Defense Criminal Investigative Service (DCIS), and private industry partners CrowdStrike and the Shadowserver Foundation.
US and European authorities disrupt Sality botnet after 23 years
US and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide. The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense Criminal Investigative Service (DCIS), CrowdStrike, the Shadowserver Foundation, and Europol. CrowdStrike’s Counter Adversary Operations team … The post US and European authorities disrupt Sality botnet after 23 years appeared first on CyberInsider .
Global sinkhole operation ends Sality botnet’s 23-year run
Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cut Sality’s operator off from every infected machine still under their control. Sality first appeared in 2003 as a file-infecting virus, the kind that attaches itself to executable programs and spreads whenever an infected … More → The post Global sinkhole operation ends Sality botnet’s 23-year run appeared first on Help Net Security .
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
The U. S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U. S. , Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that
CrowdStrike launches cyber frontier AI models, agentic security system
CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.Con conference in Las Vegas. At the heart of SafeMind are two purpose-built cybersecurity models, the adversarial Red Tempest and the defensive Blue Solano. Both models have been trained on CrowdStrike’s Falcon sensor telemetry, a security data set Kurtz called the largest in the world, drawing from “the trillions of events Falcon sensors see every day,” as well as “15 years of stopping breaches,” a reference to the company’s incident response fieldwork and threat intelligence.
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
Picus Joins CrowdStrike Project QuiltWorks to Make Organizations Mythos-Ready with Unified Validation
Machine-speed validation across every asset, exposure, and control, working with the coalition to achieve proven resilience against AI-powered attacks. Picus Joins CrowdStrike Project QuiltWorks to Make Organizations Mythos-Ready with Unified Validation
Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations
Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments. The company said the incident was detected on August 25, 2026. It caused a network outage involving certain internal information technology systems and business applications. The medical device manufacturer has engaged CrowdStrike and other third-party cybersecurity specialists to investigate, contain, and recover from the incident. In its latest update issued August 30 at 8:25 p. m. ET, Boston Scientific said it had found no indication of unauthorized activity in its environment since August 25. The company said the incident is limited to certain on-premises systems. Its cloud-based systems and applications have not been impacted, according to the ongoing investigation.
The Collective Cyber Defense letter wrote your next vendor questionnaire
Last week, more than 100 companies and organizations published an open letter calling for a rapid acceleration of cyber defense capabilities to combat the capabilities of AI. The list reads like a procurement catalog. Microsoft, Google, AWS, Cisco, IBM, CrowdStrike, Cloudflare, Anthropic, Okta and Fortinet are on it, alongside buyers like Mastercard, Visa and Capital One. The public signatory page has since passed 200 companies and organizations, with some such as 1Password, Sophos and Prophet Security, have already published posts of their own detailing their commitment to defenders. The explanations are worth sitting with. Letters turn into marketing assets faster than they become company concrete action. The buyers decide which one becomes reality. The diagnosis is correct I want to be careful about how the skepticism below reads, because the letter has the substance right.
Agents of Chaos: A New $100K Agentic Security Challenge
CrowdStrike • Agents of Chaos: An Immersive AI Security Challenge
