Sunday, September 8, 2024
HomeEconomyCrowdStrike update that caused global outage may have bypassed checks, experts say

CrowdStrike update that caused global outage may have bypassed checks, experts say

Date:

Related stories

NASA Inspector General Issues Scathing Report on SLS Delays

NASA's efforts to return humans to the moon have...

USA Swimming Replaces CEO Tim Hinchey, Team Manager Lindsey Mintenko

In the wake of an uninspiring performance at the...

How Google’s New Gemini Gems AI Experts Can Boost SEO

Google has announced a new feature for Gemini AI...

Ukraine’s F-16 fighter jet crashes – pilot dead

According to the military, a new F-16 fighter jet...

Global banks, airlines, hospitals and government offices were disrupted. CrowdStrike has released information to fix the affected systems, but experts said it will take time to get them back up and running because it requires manually removing the faulty code.

“It seems like the scan or protection they do when they look at the code, maybe that file wasn’t included in that or it slipped through somehow,” said Steve Cobb, chief security officer at Security Scorecard, some of whose systems were also affected by the issue.

The problems surfaced quickly after the update was rolled out on Friday, with users posting photos on social media of computers with blue screens displaying error messages. These are known in the industry as “blue screens of death.”

Patrick Wardle, a security researcher who specializes in studying threats against operating systems, said his analysis identified the code responsible for the outage.

He said the issue with the update was “with a file that contains either configuration information or signatures.” These signatures are code that detects certain types of malicious code or malware.

“It is very common for security products to update their signatures, once a day… because they are constantly monitoring new malware and because they want to make sure their customers are protected from the latest threats,” he said.

He said the pace of updates “may be why CrowdStrike hasn’t tested it much.”

It is unclear how this buggy code made its way into the update and why it was not discovered before it was released to customers.

See also  Jeff Bezos asks the Council on Disinformation to verify the authenticity of Biden's tweet

“Ideally, this technology would have been rolled out to a limited group first,” said John Hammond, principal security researcher at Huntress Labs. “This is a safer approach to avoid a major mess like this.”

Other security companies have faced similar incidents in the past. A flawed McAfee antivirus update in 2010 took hundreds of thousands of computers offline.

But the global impact of the outage reflects CrowdStrike’s dominance. More than half of Fortune 500 companies and many government agencies, including the nation’s largest cybersecurity agency, the Cybersecurity and Infrastructure Security Agency, use the company’s software.

Latest stories