Skip to main content

CrowdStrike

See All Stories

CrowdStrike largest IT outage in history; cost more than $5B

CrowdStrike largest IT outage in history | Windows BSOD shown

Cybersecurity researcher Troy Hunt – who runs the HaveIBeenPwned website – predicted that the CrowdStrike failure would set a record as the largest IT outage in history, and the numbers seem to back him up.

Cyber insurance company Parametrix has put together some estimates of the cost of the outage, with healthcare companies worst hit, and airlines not far behind …

Expand Expanding Close

CrowdStrike CEO called to testify before Congress to explain how it happened

CrowdStrike CEO called to testify before Congress | Committee on Homeland Security graphic

The House Homeland Security Committee has written to CrowdStrike CEO George Kurtz, asking him to testify before Congress. The letter says the committee wants Kurtz to explain how the global IT outage happened, and what steps it is taking to prevent any repetition.

The demand comes as companies around the world struggle to recover from the global IT outage, with Delta saying that it has cancelled 4,000 flights since Friday and expects disruption to continue for another couple of days …

Expand Expanding Close

CrowdStrike aftermath: Microsoft claims it cannot legally implement the same protections as Apple

CrowdStrike aftermath – Macs unaffected | Happy Mac icon

The CrowdStrike aftermath is seeing IT teams around the world struggle to restore the 8.5 million Windows PCs taken out by the bug. The mess included thousands of flights cancelled, health centers unable to make appointments, retailer payment terminals down, and even some 911 services unavailable.

Macs weren’t affected thanks to protections put in place by Apple, but Microsoft has reportedly claimed that antitrust law means it’s unable to take the same approach …

Expand Expanding Close

Global IT outage takes down airlines, banks, 911 services, more; CrowdStrike to blame

Global IT outage caused by CrowdStrike | Screengrab of crashed Windows PC

A huge mistake by cybersecurity company CrowdStrike has caused a global IT outage on a massive scale, with airlines, banks, health services, and more affected – including some 911 centers.

United, Delta, and American Airlines are among the airlines who have been forced to ground flights. Broadcaster Sky News was taken off-air for several hours. Many retailers have been unable to accept payments. In short, it’s chaos out there …

Expand Expanding Close

Apple patched a major SSL bug in iOS yesterday, but OS X is still at risk

Site default logo image

Update: Apple says an OS X fix is coming soon.

Yesterday Apple released iOS update 7.0.6 alongside new builds for iOS 6 and Apple TV  that it said provided “a fix for SSL connection verification.” While Apple didn’t provide much specific information on the bug, it wasn’t long before the answer was at the top of Hacker News. It turns out that minor security fix was actually a major flaw that could in theory allow attackers to intercept communications between affected browsers and just about any SSL-protected site. Not only that, but the bug is also present in current builds of OS X that Apple has yet to release a security patch for.

Researchers from CrowdStrike described the bug in a report:

“To pull off the attack an adversary has to be able to Man-in-The-Middle (MitM) network connections, which can be done if they are present on the same wired or wireless network as the victim. Due to a flaw in authentication logic on iOS and OS X platforms, an attacker can bypass SSL/TLS verification routines upon the initial connection handshake. This enables an adversary to masquerade as coming from a trusted remote endpoint, such as your favorite webmail provider and perform full interception of encrypted traffic between you and the destination server, as well as give them a capability to modify the data in flight (such as deliver exploits to take control of your system),”

Adam Langley, a senior software engineer at Google, also wrote about the flaw on his blog ImperialViolet and created a test site to check if you have the bug (pictured above):
Expand
Expanding
Close

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications