{"id":4566,"date":"2024-07-22T07:00:00","date_gmt":"2024-07-22T12:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/fallout-from-faulty-friday-crowdstrike-update-persists"},"modified":"2024-07-22T07:00:00","modified_gmt":"2024-07-22T12:00:00","slug":"fallout-from-faulty-friday-crowdstrike-update-persists","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/22\/fallout-from-faulty-friday-crowdstrike-update-persists\/","title":{"rendered":"Fallout from Faulty Friday CrowdStrike Update Persists"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfb56725164d82e72\/669addb01170a6590e755b53\/blue_screen_of_death.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Echoes of the July 19 CrowdStrike glitch are likely to reverberate across the industry for years to come. For now, IT teams remain focused on slogging through a labor-intensive recovery.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But recovery is just the beginning. What&#8217;s sure to follow is a barrage of regulatory oversight, hard feelings among the IT community, and a tough reminder that even a small slip-up in a software update can have catastrophic global consequences.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyber adversaries have also started to circle, eyeing an opportunity.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Windows in Recovery Mode\">Windows in Recovery Mode<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The faulty sensory configuration update to the Falcon Platform was released on July 19 at 4:09 UTC, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/blog\/technical-details-on-todays-outage\/\" rel=\"noopener\">according to CrowdStrike<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Once the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/crowdstrike-outage\" rel=\"noopener\">CrowdStrike update<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> was pushed out, it triggered widespread Microsoft outages <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/technology\/what-is-crowdstrike-cybersecurity-firm-behind-global-tech-outage-2024-07-19\/#:~:text=WHO%20ARE%20CROWDSTRIKE'S%20MAJOR%20CLIENTS,new%20tab%20are%20its%20customers.\" rel=\"noopener\">across CrowdStrike&#8217;s 29,000 customers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> who rely on the company&#8217;s software for cybersecurity endpoint detection and response (EDR). CrowdStrike&#8217;s customers include retailers Target and Amazon, tech giants Alphabet and Intel, as well as many other household company names. When they tried to log on Friday morning, employees at some of the world&#8217;s largest organizations were left staring at the dreaded blue screen of death. Airports, banks, hospitals, governments \u2014 there were few sectors spared the fallout \u2014 paralyzing the world&#8217;s economy and causing panic.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It wasn&#8217;t a cyberattack, CrowdStrike assured the world, just a glitch. But that was little comfort to IT teams who faced Friday with the task of manually booting affected PCs into recovery mode, deleting the bad file, and restarting. That process is still underway in many organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is not something that can be done remotely, and in many organizations, will require an administrator,&#8221; said Tom Marsland, vice president of technology for Cloud Range, in a statement. &#8220;This means someone from IT support going computer to computer and doing this manually.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Marsland predicted the recovery will take days, even a week or more, for some larger companies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Recovery is going to be painful, to put it lightly,&#8221; Marsland added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Microsoft crash was unrelated to a July 18 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/azure.status.microsoft\/en-gb\/status\/history\/\" rel=\"noopener\">Azure outage<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which has already been remediated, according to a Microsoft spokesperson.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Microsoft, which says it has been working closely with CrowdStrike on remediating the issue, some 8.5 million Windows devices &#8211; less than 1% of all Windows machines &#8212; were affected by the flawed update.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This incident demonstrates the interconnected nature of our broad ecosystem \u2014 global cloud providers, software platforms, security vendors and other software vendors, and customers. It\u2019s also a reminder of how important it is for all of us across the tech ecosystem to prioritize operating with safe deployment and disaster recovery using the mechanisms that exist,&#8221; said David Weston, vice president of enterprise and OS security at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blogs.microsoft.com\/blog\/2024\/07\/20\/helping-our-customers-through-the-crowdstrike-outage\/\" rel=\"noopener\">Microsoft in a post over the weekend<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CrowdStrike Glitched\">CrowdStrike Glitched<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So how did a CrowdStrike update crash the world&#8217;s computers? It&#8217;s what they didn&#8217;t do that was problematic, experts say.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">David Brumley, a professor of Electrical and Computer Engineering Department at Carnegie Mellon University, sees a couple mistakes CrowdStrike made: in testing and the rollout.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;First, they didn&#8217;t stress-test their updates enough,&#8221; Brumley said in a statement provided to Dark Reading. &#8220;This needs to be done at two stages: stress-testing software components before they are assembled, and stress-testing the final software builds across operating system versions.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The missteps continued, according to Brumley.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Second, they were not incremental enough in their rollout,&#8221; he added. &#8220;That means everyone got the bad update at once. Companies like Google will roll out updates incrementally so if the update is bad, at least it will have limited damage.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s also the matter of rolling out the update on a Friday &#8212; a practice widely considered among IT professionals to be poor form.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Deploying updates on a Friday is generally a bad idea due to several risks, as highlighted by the CrowdStrike incident,&#8221; says Callie Guenther, senior manager, cyber threat research, at Critical Start. &#8220;Typically, IT teams are understaffed over the weekend, so if an update goes wrong, there are fewer people available to fix it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">She adds Friday rollouts also increase the odds the issue will go unnoticed over the weekend.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"'Huge Deal'\">&#8216;Huge Deal&#8217;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As CrowdStrike claws out of this incident, the company is likely to face a whirlwind of scrutiny. The wisdom of rampant consolidation of software vendors is also likely to be examined, Andy Ellis, operating partner at YL Ventures, tells Dark Reading.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I suspect that every regulator with even a smidgen of authority will be investigating, even if just to explore the vendor consolidation risk across so many different critical industries,&#8221; Ellis says. &#8220;This has exposed how much of a monoculture our core infrastructure relies on.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">By Friday afternoon, Federal Trade Commission chair Linda Khan seemed to make reference to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/linakhanFTC\/status\/1814395610788929649?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1814395610788929649%7Ctwgr%5E79090bdcc7be1b22571474eeaf995e07f1f820fb%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fiframe.nbcnews.com%2F0gpg5CS%3F_showcaption%3Dtrueapp%3D1\" rel=\"noopener\">CrowdStrike outage<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on social media and noted the reliance on too few vendors has created &#8220;fragile systems,&#8221; where a &#8220;&#8230; single glitch results in a system-wide outage.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond lost profits and hours of work needed in the aftermath of the CrowdStrike outage, adversaries are already trying to capitalize. Both CrowdStrike&#8217;s CEO George Kurtz and CISA warned that scammers are looking to take advantage of the chaos.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We know that adversaries and bad actors will try to exploit events like this,&#8221; Kurtz said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/blog\/our-statement-on-todays-outage\/\" rel=\"noopener\">statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;I encourage everyone to remain vigilant and ensure that you&#8217;re engaging with official CrowdStrike representatives.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As for CrowdStrike, the company will need to convince customers this is a one-off bungle. Contracts will likely protect CrowdStrike from any legal liability, Ellis explains, adding ultimately it will be up to their customers to decide the company&#8217;s fate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I suspect, like most software companies, that contractual limitations on liability will directly protect CrowdStrike, but that doesn\ufffd\ufffd\u2019t protect them from hard conversations with regulators, or with customers during their renewal cycles,&#8221; Ellis adds. &#8220;This is a huge deal.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/fallout-from-faulty-friday-crowdstrike-update-persists\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Echoes of the July 19 CrowdStrike glitch are likely to<\/p>\n","protected":false},"author":12,"featured_media":4567,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=2560%2C1601&ssl=1",2560,1601,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=300%2C188&ssl=1",300,188,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=640%2C400&ssl=1",640,400,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=640%2C400&ssl=1",640,400,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=1536%2C961&ssl=1",1536,961,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=2048%2C1281&ssl=1",2048,1281,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=1024%2C640&ssl=1",1024,640,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/fallout-from-faulty-friday-crowdstrike-update-persists-scaled.jpg?fit=2560%2C1601&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4566"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4566\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4567"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}