keneci Network
News • Science & Tech • Comedy
CrowdStrike, Microsoft Release Preliminary Reports Following Disruptive Buggy Software Update That Affected Windows Computers Worldwide
July 29, 2024
post photo preview

Following the cybersecurity company's July 19 software update debacle which affected Windows computers worldwide, and the ensuing disruptions, CrowdStrike has released a Preliminary Post Incident Review(PIR) on the Content Configuration Update Impacting the Falcon Sensor and the Windows Operating System (BSOD). This will be more detailed in the company's full investigation in the forthcoming Root Cause Analysis that will be released publicly, according to CrowdStrike.

"On Friday, July 19, 2024 at 04:09 UTC, as part of regular operations, CrowdStrike released a content configuration update for the Windows sensor to gather telemetry on possible novel threat techniques," the company wrote in the preliminary review. "These updates are a regular part of the dynamic protection mechanisms of the Falcon platform. The problematic Rapid Response Content configuration update resulted in a Windows system crash. Systems in scope include Windows hosts running sensor version 7.11 and above that were online between Friday, July 19, 2024 04:09 UTC and Friday, July 19, 2024 05:27 UTC and received the update. Mac and Linux hosts were not impacted. The defect in the content update was reverted on Friday, July 19, 2024 at 05:27 UTC. Systems coming online after this time, or that did not connect during the window, were not impacted."

As to what Went wrong and why? The company writes: "CrowdStrike delivers security content configuration updates to our sensors in two ways: Sensor Content that is shipped with our sensor directly, and Rapid Response Content that is designed to respond to the changing threat landscape at operational speed. The issue on Friday involved a Rapid Response Content update with an undetected error."

The report continues:

"Sensor Content provides a wide range of capabilities to assist in adversary response. It is always part of a sensor release and not dynamically updated from the cloud. Sensor Content includes on-sensor AI and machine learning models, and comprises code written expressly to deliver longer-term, reusable capabilities for CrowdStrike’s threat detection engineers.

"These capabilities include Template Types, which have pre-defined fields for threat detection engineers to leverage in Rapid Response Content. Template Types are expressed in code. All Sensor Content, including Template Types, go through an extensive QA process, which includes automated testing, manual testing, validation and rollout steps.

"The sensor release process begins with automated testing, both prior to and after merging into our code base. This includes unit testing, integration testing, performance testing and stress testing. This culminates in a staged sensor rollout process that starts with dogfooding internally at CrowdStrike, followed by early adopters. It is then made generally available to customers. Customers then have the option of selecting which parts of their fleet should install the latest sensor release (‘N’), or one version older (‘N-1’) or two versions older (‘N-2’) through Sensor Update Policies.

"The event of Friday, July 19, 2024 was not triggered by Sensor Content, which is only delivered with the release of an updated Falcon sensor. Customers have complete control over the deployment of the sensor -- which includes Sensor Content and Template Types."

Microsoft in a blog post, also examined the CrowdStrike outage and provided a technical overview of the root cause.

The computing giant explains why security products use kernel-mode drivers today and the safety measures Windows provides for third-party solutions. And shares how customers and security vendors can better leverage the integrated security capabilities of Windows for increased security and reliability. Microsoft also provides a look into how Windows will enhance extensibility for future security products.

Microsoft also confirms CrowdStrike’s analysis that this was a read-out-of-bounds memory safety error in the cybersecurity developed CSagent.sys driver.


CrowdStrike Software Bug Causes Global IT Outage, Disruptions In Aviation, Other Sectors

A software update from a United States cybersecurity firm CrowdStrike on Friday(July 19), caused a widespread IT outage and 'blue screens of death,' affecting millions of Microsoft Windows devices worldwide. The incident resulted in significant disruptions to various industries, including aviation.

Hundreds of flights were canceled or delayed globally, with Delta Air Lines being particularly affected. The outage impacted airport systems, including baggage handling and security screening, causing long lines and congestion at the airports, as passengers were unable to check in or access flight information.

Many Fortune 500 companies, including airlines, are estimated to have lost up to $5.4 billion in revenues and gross profit due to the outage. The health care and banking sectors were also severely affected, with estimated losses of $1.94 billion and $1.15 billion, respectively.

In the United Kingdom, some hospitals experienced issues with electronic patient records and medical equipment. Flights were canceled or delayed, with British Airways and EasyJet among the airlines affected. Firms relying on CrowdStrike’s cybersecurity services, such as security monitoring and incident response, were also affected. Ambulance and fire services faced difficulties with communication and dispatch systems.

Also impacted in the the UK, are thousands of businesses and organizations using Microsoft products, such as Windows and Office. Amazon Web Services (AWS) users also experienced issues with their cloud services.

The cybersecurity firm has since released a software update to fix the bug.

CrowdStrike CEO George Kurtz faced backlash for his initial response on X, to the debacle. “CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts,” Kurtz wrote Friday. “Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed.”

Kurtz initially struggled to provide a timeline for when systems would be restored, leaving customers and regulators in the dark. His response was criticized for being too technical and lacking a personal touch.

Lulu Meservey, chief executive of public relations company Rostra, posted a scathing critique of the statement on social media platform X earning over 15,000 likes as she lambasted Kurtz for using “weapons-grade corpo speak.”

“Let’s be clear. Legalese doublespeak is designed to dodge and obfuscate rather than inform or communicate,” said Meservey. “This statement was obviously written by a committee of lawyers and middle managers whose only goal was to avoid legal risk and threats to their own job security. If you can’t understand what the statement is even saying, it’s working as intended.”

She criticised Kurtz for adopting a “passive voice” and described the statement as “almost comical in its efforts to dodge assigning responsibility,” before pointing out a lack of an apology.

“The first words should be ‘I’m sorry,’” she said. “This outage knocked out 911 call centres and hospitals. People literally might have died. And the company’s CEO is out here playing it down as if it’s not a big deal.”

To make matters worse, CrowdStrike offered a $10 UberEats voucher as a token of apology to its staff and partners. This gesture was widely panned as insufficient and insensitive, particularly given the significant financial losses incurred by affected businesses, estimated to be around $5.4 billion.

Kurtz, in a statement on the company’s website late on Friday afternoon, apologized once again for the outage and said that CrowdStrike was working to help restore systems.

“Nothing is more important to me than the trust and confidence that our customers and partners have put into CrowdStrike,” Kurtz said. “As we resolve this incident, you have my commitment to provide full transparency on how this occurred and steps we’re taking to prevent anything like this from happening again.”

The CEO told NBC’s Today Show in the US that the problem was down to a bug in a single update. “We identified this very quickly and remediated the issue,” he said, adding that CrowdStrike was now “working with each and every customer to make sure that we can bring them back online.”

Kurtz said there had been a “negative interaction” between the update and Microsoft’s operating system, which had then caused computers to crash, sparking the global outage, which remains ongoing.

Asked how one faulty update could cause such global chaos, he said: “We have to go back and see what happened here, our systems are always looking for the latest attacks from adversaries that that are out there.”

He reiterated that there was no possibility it was a cyber-attack. However, although the problem had been identified and a fix issued, Kurtz said “it could be some time for some systems” to return to normal, stressing that they would not “just automatically recover.”

Authorities in the UK and the US Department of Transportation are investigating the incident, and airlines are reviewing their contingency plans to mitigate the impact of future outages. Kurtz is due to testify in a US congressional hearing.

 

community logo
Join the keneci Network Community
To read more articles like this, sign up and join my community today
0
What else you may like…
Videos
Posts
Articles
SpaceX Starlink Internet Satellites

With Starlink internet, data is continuously being sent between a ground dish and a Starlink satellite orbiting 550km above. Furthermore, the Starlink satellite zooms across the sky at 27,000 km/hr! MORE VIDEOS ON KENECI NETWORK RUMBLE CHANNEL: https://rumble.com/c/Keneci

00:28:08
Elon Musk, DOGE Speak On Waste And Fraud

US Department of Government Efficiency Services (USDS) led by Elon Musk speak on the "mind-boggling" fraud and waste in UInited States federal government

00:00:45
January 17, 2025
SpaceX Launches Starship 7th Test Flight

SpaceX successfully executed its second-ever “chopsticks” catch of a Super Heavy booster (or Booster 14) using the “Mechazilla” launch tower on Thursday(Jan. 16), during the seventh uncrewed test flight of the company's 123-meter Starship rocket. However, the megarocket's upper stage(or Ship 33) was lost approximately 8.5 minutes into the flight in a “rapid unscheduled disassembly(RUD)” or explosion

00:10:30
Welcome to Keneci Network!

Join the conversations!

December 09, 2025
Bitcoin White Paper By Satoshi Nakamoto

Bitcoin white paper

Bitcoin_White_Paper.pdf
September 17, 2024
Charges Against Sean 'Diddy' Combs In Grand Jury Indictment

The rapper was charged with racketeering conspiracy, sex trafficking by force, fraud or coercion, and transportation to engage in prostitution in the indictment unsealed Tuesday(Sept. 17)

Combs-Indictment-24-Cr.-542.pdf
post photo preview
SpaceX Wins 2.29B US Space Force Contract To Build Space Data Network

The U.S. Space Force awarded SpaceXAI a $2.29 billion fixed-price Other Transaction Authority (OTA) contract to develop the Space Data Network (SDN) Backbone, a proliferated low Earth orbit (pLEO) satellite constellation designed for secure, high-speed military communications.

The agreement covers the SDN Backbone, a resilient network architecture providing high-capacity, low-latency data transport for connecting military sensors and weapons platforms globally. SpaceXAI must deliver a fully operational prototype capability by the end of 2027.

The system utilizes an expanded optically interconnected mesh of satellites to deliver worldwide low latency tactical communications and broadband services, functioning alongside the Space Development Agency’s (SDA) Transport Layer to form a unified Department of Defense data transport architecture.

The network is foundational to the Golden Dome missile defense initiative, providing the communications pathways to move data from missile warning sensors to interceptors in near real time.

While SpaceX is currently the sole provider for the backbone (formerly known as MILNET), the Space Force plans to identify additional contractors for satellite construction and other network elements to galvanize the U.S. industrial base.

Read full Article
post photo preview
US Targets Iran In 'Self-defense' Strikes, After Speedboat Mine-laying Incident, As Israeli Bombing Of Lebanon Intensifies In Operation Arrows Of Fire

Israeli Prime Minister Benjamin Netanyahu vowed Monday, to "crush" Hezbollah and intensify airstrikes in Lebanon, while U.S. Central Command conducted defensive strikes against Iranian targets in Bandar Abbas and the Strait of Hormuz in response to mine-laying activities.

Netanyahu announced he would "increase the blows" and firepower against Hezbollah, citing the group's use of fiber-optic drones to attack Israeli forces. The Israeli Air Force struck more than 70 Hezbollah sites, including command centers and weapons depots in southern Lebanon and the Bekaa Valley, as it launched Operation Arrows of Fire.

Residents in Beirut’s southern suburbs were seen fleeing as evacuation orders were issued for villages in southern Lebanon; Israeli strikes reportedly killed three people in the region.

Despite a US-brokered ceasefire with Iran that took effect in April, Israel maintains that the agreement does not cover Hezbollah, leading to continued cross-border hostilities and accusations of ceasefire violations from both sides.

Iran’s Foreign Minister Abbas Araghchi expressed support for Hezbollah, while in Doha, Qatar, with Iranian Parliament Speaker Mohammad Bagher Ghalibaf on Monday, to discuss terms for a regional settlement that would reopen the Strait of Hormuz.

Israeli security elites, Jewish supremacists in government and political commentators have criticized Netanyahu’s alignment with US diplomatic efforts, warning that a deal could empower Iran and damage Israel’s strategic position.

Meanwhile the US military launched strikes on southern Iran, targeting Revolutionary Guard(IRGC) vessels and a surface-to-air missile(SAM) site in Bandar Abbas, which it described as defensive actions against threats to US forces. Targets included Bandar Abbas airport, Shahid Bahonar pier, and possibly Mount Mubarak in Jask.

"U.S. forces conducted self-defense strikes in southern Iran today to protect our troops from threats posed by Iranian forces," CENTCOM's Captain Tim Hawkins said. "Targets included missile launch sites and Iranian boats attempting to emplace mines. U.S. Central Command continues to defend our forces while using restraint during the ongoing ceasefire"

The attacks followed reports that Iranian boats were laying mines in the Strait of Hormuz, a vital waterway for global oil transport. Two IRGC Navy speedboats were reportedly attacked last night. Iran reportedly responded by downing about two US MQ-9 drones, and firing at U.S. warships in the Gulf of Oman, which then allegedly triggered American strikes on the eastern side of Bandar Abbas and the activation of Iranian air defenses.

US officials said the strikes were conducted "with restraint" during the ongoing ceasefire and did not indicate its collapse, though explosions were heard across the region.

These military actions occurred simultaneously with high-stakes peace talks between the US and Iran, led by Trump’s administration, which is pushing for Iran to hand over or destroy its enriched uranium stockpile under IAEA oversight.

President Donald Trump appeared to soften US position on the fate of the highly enriched Uranium stockpile in Iran, which he had demanded be handed over to the US in any future peace deal.

"The Enriched Uranium (Nuclear Dust!) will either be immediately turned over to the United States to be brought home and destroyed or, preferably, in conjunction and coordination with the Islamic Republic of Iran, destroyed in place or, at another acceptable location, with the Atomic Energy Commission, or its equivalent, being witness to this process and event. Thank you for your attention to this matter!" Trump wrote on Truth Social early morning Tuesday.

The US president on Monday, also issued a lengthy Truth Social post, saying he had spoken with Gulf Arab leaders and stipulated that any deal to end the Iran war should require them to sign the Abraham Accords, which normalized relations between Israel and a handful of Middle Eastern countries. A demand rejected out of hand by officials in Qatar, Saudi Arabia and Pakistan, Monday.

Strait of Hormuz blockade have caused oil prices to fluctuate, with West Texas Intermediate falling below $91.33 a barrel on optimism for a deal, while Brent crude remained near $97.68.

Read full Article
post photo preview
Flight 12: SpaceX Launched Upgraded Starship V3 Megarocket In Spectacular Test Mission

SpaceX successfully launched Starship Flight 12 on Friday, (May 22), at 2230 UTC, marking the debut of the Starship V3 megarocket from the new Pad 2 at Starbase, Texas. The 407-foot-tall (124 meters) vehicle, generating up to 18 million pounds of thrust, completed its 12th suborbital test flight, achieving most primary objectives despite minor engine anomalies.

The first notable event after the rocket cleared the tower occurred about 2 minutes and 20 seconds into flight, when Super Heavy initiated "hot staging" and separation from Ship. (It's known as hot staging because Ship begins firing its engines before separating from Super Heavy.)

The Super Heavy booster (first stage or Booster 19) experienced a single Raptor engine shutdown during ascent and failed to complete its planned "boost back" burn due to additional engine irregularities, resulting in a splashdown in the Gulf of Mexico short of the target.

Meanwhile, the Starship upper stage (Ship 39) also lost one of its six Raptor engines during ascent but compensated by keeping the remaining five active longer, successfully reaching an acceptable suborbital trajectory.

"I wouldn't call it nominal orbital insertion, but we're in on a trajectory that we had analyzed, and it's within bounds," SpaceX spokesperson Dan Huot said in live commentary. "So, teams continuing to work through it with that engine out there, working some through some steps on the engines."

After stage separation, Super Heavy reoriented and attempted to perform a one-minute boostback burn toward Starbase. However, something went wrong and the burn didn't go as planned, Huot said.

"The booster didn't complete its full boost back," Huot said just after lifotff. "Its mission ended a little bit early, but landed in the clear area that we had set in advance."

During the suborbital cruise phase, Starship deployed 22 payloads, including 20 dummy Starlink satellites and two modified Starlink spacecraft ("Dodger Dogs"). These two satellites carried cameras that captured images of the Starship heat shield tiles, providing data to assess thermal protection integrity for future missions. A planned in-space re-ignition of a Raptor engine was skipped due to the earlier engine loss.

Shortly after the final two Starlink simulators deployed (the ones with cameras that SpaceX nicknamed "Dodger Dogs" after the famed hotdogs at Dodger Stadium), SpaceX broadcast the spectactular video they captured as they flew away from Starship.

"That is a Starship in space," Huot said.

"Congratulations SpaceX team on an epic first Starship V3 launch & landing!," SpaceX CEO Elon Musk wrote on X after the launch. "You scored a goal for humanity."

Ship 39 began its reentry to Earth's atmosphere about 50 minutes into the flight, falling as its belly became engulfed in a bright plasma. During its descent, Ship 39 performed a series of exercises designed to stress parts of the vehicle to their structural limit. It also executed a novel banking maneuver for its landing burn meant to mimic the trajectory and orientation needed for a launch tower catch on a return to Starbase.

Huge cheers rang out at SpaceX's headquareters and Starbase facilities as the Ship 39 ignited two engines for a final landing burn. The manuever initially called for three engines, but that one shut down early at liftoff. After the landing, Starship toppled over into the ocean waters and exploded in a magnificent fireball (again, as planned) as SpaceX workers cheered.

Friday'he launch occurred following delays Thursday, caused by a stuck hydraulic pin and weather.

Starship V3 features significant upgrades over its predecessors, including Raptor 3 engines, larger fuel tanks, and docking ports for in-orbit refueling—a critical capability for NASA’s Artemis moon landing program.

Unlike its V2 predecessor, which featured an interstage ring that fell away at separation, Starship V3 is built with similar hardware secured to the top of the booster, like a fence around the fuel tank's dome to give some breathing room to the upper stage engines' ignition and initial thrust away from the booster.

The vehicle is designed to be fully reusable, with NASA targeting Starship as the lunar lander for Artemis 3 (scheduled for 2027/2028). "We're looking forward to seeing this thing fly, because hopefully at some point in the not too distant future we're gonna, we're gonna join up in an earth orbit," NASA Administrator Jared Isaacman, who was present at the launch, said during the live comentary.

NASA is relying on Starship as one of the crewed lunar landers for its Artemis program, which aims to eventually establish a permanent human presence on the moon. The space agency has also contracted Blue Moon, a Blue Origin spacecraft, to land Artemis astronauts on the moon, and has indicated a willingness to fly with whichever private lander is ready when it's time for the missions to get off the ground.

The next of those missions is Artemis 3 — the follow-up to April's Artemis 2, which flew four astronauts aboard NASA's Orion spacecraft on a successful 10-day mission around the moon. NASA is targeting mid to late 2027 for Artemis 3, which will launch Orion to low Earth orbit (LEO) to rendezvous and dock with one or both of the private lunar landers, and late 2028 for the first lunar landing on Artemis 4.

After the launch, Isaacman hailed the work of SpaceX's Starship team.

"Congrats SpaceX team and Elon Musk on a hell of a V3 Starship launch," Isaacman wrote on X. "One step closer to the Moon ... one step closer to Mars."

Starship has a number of boxes to check before NASA certifies the vehicle to fly astronauts, but V3 has been built with those goalposts in mind. For example, NASA is requiring both Starship and Blue Moon to demonstrate uncrewed lunar landings before they fly astronauts down to the lunar surface, putting SpaceX and Blue Origin on a short timeline to ready vehicles for the planned Artemis 4 landing in 2028.

Flight 12 represents a major milestone ahead of SpaceX’s anticipated initial public offering (IPO) in June.

Read full Article
See More
Available on mobile and TV devices
google store google store app store app store
google store google store app tv store app tv store amazon store amazon store roku store roku store
Powered by Locals