Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CrowdStrike to Acquire Onum to Transform How Data Powers the Agentic SOC

Today, I’m excited to announce CrowdStrike’s agreement to acquire Onum, a leader in real-time telemetry pipeline management that will extend the CrowdStrike Falcon platform’s data advantage. Onum delivers the real-time data architecture to transform data in motion into high-fidelity intelligence, fueling CrowdStrike Falcon Next-Gen SIEM and powering the agentic SOC. This is a pivotal step forward in our mission to stop breaches.

CrowdStrike Named a Leader in 2025 IDC MarketScape for Worldwide Incident Response Services

CrowdStrike has been named a Leader in the IDC MarketScape: Worldwide Incident Response Services 2025 Vendor Assessment. We believe this validation reflects CrowdStrike’s strength in delivering rapid, effective response, powered by the AI-native CrowdStrike Falcon platform, frontline breach expertise, and a global 24/7 incident response model designed for today’s most advanced threats.

CrowdStrike Named a Leader in 2025 IDC MarketScape for Exposure Management

CrowdStrike has been named a Leader in the 2025 IDC MarketScape: Worldwide Exposure Management 2025 Vendor Assessment. CrowdStrike has redefined exposure management to meet the realities of today’s threat landscape, where modern adversaries move fast, exploit stolen credentials, and use malware-free techniques to bypass defenses and blend into legitimate operations across endpoint, identity, cloud, and unmanaged infrastructure.

Executive Exposure Reports with Charlotte AI

This demo shows how Charlotte AI transforms raw vulnerability data from Falcon Exposure Management into a CISO-ready report. By pulling enriched insights from Next-Gen SIEM—like ExPRT.AI scores and asset criticality—the workflow translates technical signals into business risk. The result: a clear, automated email that highlights key trends, impacted systems, and actionable remediation paths.

MURKY PANDA: A Trusted-Relationship Threat in the Cloud

Since 2023, CrowdStrike Services and CrowdStrike Counter Adversary Operations have investigated multiple intrusions conducted by MURKY PANDA, a sophisticated adversary leveraging advanced tradecraft to compromise high-profile targets. MURKY PANDA, active since at least 2023, is a cloud-conscious adversary with a broad targeting scope; the adversary’s operations have particularly focused on government, technology, academia, legal, and professional services entities in North America.

Executive Cloud Posture Reports with Charlotte AI: Demo Drill Down

Powered by AI, Falcon Cloud Security surfaces the most critical misconfigurations, and Charlotte AI transforms them into clear business impact to provide CISO ready reports. Subscribe and Stay Updated: ► Don't miss out on more exciting content! Subscribe to our channel for the latest updates, case studies, and more from the world of cybersecurity. Hit the bell icon to receive notifications whenever we post new videos.

Falcon Platform Prevents COOKIE SPIDER's SHAMOS Delivery on macOS

Between June and August 2025, the CrowdStrike Falcon platform successfully blocked a sophisticated malware campaign that attempted to compromise over 300 customer environments. The campaign deployed SHAMOS, a variant of Atomic macOS Stealer (AMOS) developed by the cybercriminal group COOKIE SPIDER. Operating as malware-as-a-service, COOKIE SPIDER rents this information stealer to cybercriminals who deploy it to harvest sensitive information and cryptocurrency assets from victims.

Live at Black Hat: What's AI Really Capable Of?

"This year at Black Hat, the topic of AI was everywhere — from hallway chats to the expo floor. Adam and Cristian took a break from the action for a rare in-person conversation about how adversaries are weaponizing AI, how defenders are using agentic AI, and what we should all be thinking about as AI evolves as an offensive and defensive tool.

See Falcon Next-Gen Identity Security in Action

Traditional identity and access management (IAM) and privileged access management (PAM) solutions are unprepared to face modern identity attacks. These solutions are primarily built to manage access — not secure it. Falcon Next-Gen Identity Security combines proactive prevention, modern secure privileged access, identity threat detection and response (ITDR), SaaS identity security, and agentic identity protection to stop identity-driven attacks.

Defending Against SCATTERED SPIDER with Falcon Next-Gen SIEM

SCATTERED SPIDER is a prolific eCrime adversary that has conducted a range of financially motivated activities beginning in early 2022. Since surfacing, this adversary continues to compromise organizations around the world, deploying ransomware and exfiltrating sensitive files.

Falcon Next-Gen Identity Security Unifies Protection Across All Identities and Domains

CrowdStrike is excited to announce CrowdStrike Falcon Next-Gen Identity Security, a new solution built to protect every identity — human, non-human, and AI agent — across on-premises, cloud, and SaaS environments. This new offering addresses the growing need for comprehensive protection throughout the full identity lifecycle.

CrowdStrike Named the Only Leader in GigaOm Radar for SaaS Security Posture Management

CrowdStrike is excited to be the only vendor named a Leader and Outperformer in the 2025 GigaOm Radar Report for SaaS Security Posture Management (SSPM). The report recognizes CrowdStrike as the most innovative and complete Platform Play, demonstrating our leadership in protecting identities and SaaS environments as the enterprise attack surface evolves.

CrowdStrike's Approach to Better Machine Learning Evaluation Using Strategic Data Splitting

Since day one, CrowdStrike's mission has been to stop breaches. Our pioneering AI-native approach quickly set our platform apart from the landscape of legacy cybersecurity vendors that were heavily reliant on reactive, signature-based approaches for threat detection and response. Our use of patented models across the CrowdStrike Falcon sensor and in the cloud enables us to quickly and proactively detect threats — even unknown or zero-day threats.

Falcon Cloud Security - Proactive Security

Proactive Security provides Unified cloud security posture (USPM) and business context across cloud layers, leveraging industry leading threat intelligence, end-to-end attack paths, and ExPRT.AI to reduce alert noise by 95%. Cloud teams can swiftly prioritize their work, neutralize critical risks, and leave adversaries no room to strike. Subscribe and Stay Updated: ► Don't miss out on more exciting content! Subscribe to our channel for the latest updates, case studies, and more from the world of cybersecurity. Hit the bell icon to receive notifications whenever we post new videos.

CrowdStrike Signal: Detect the Undetectable

Modern adversaries hide in plain sight by blending malicious activity with normal system behavior, making it difficult for traditional detection tools to identify threats early. CrowdStrike Signal uses self-learning AI to turn scattered signals into high-confidence Automated Leads that help analysts stop breaches before they escalate.

CrowdStrike Launches New AI Security Services to Strengthen AI Security and SOC Readiness

AI is transforming business processes and the threat landscape. CrowdStrike is expanding our AI Security Services portfolio to help organizations meet the dual challenges of securing their AI systems and effectively integrating AI into security operations.

CrowdStrike Signal Transforms AI-Powered Threat Detection

Security teams don't need more alerts. They need the ability to detect what others miss. That's why we're excited to announce the general availability of CrowdStrike Signal, a new class of AI-powered detection that surfaces the stealthy threats others often overlook — before they escalate. CrowdStrike Signal represents a fundamental shift in how organizations detect and respond to modern threats.

CrowdStrike Announces Integration with ChatGPT Enterprise Compliance API

CrowdStrike is announcing a native integration between CrowdStrike Falcon Shield SaaS security and the OpenAI ChatGPT Enterprise Compliance API, adding visibility and security posture capabilities for mutual customers’ ChatGPT Enterprise environments. This integration helps security teams inventory and monitor AI agents across their organization — including who created them, what they access, and how they’re shared — so teams can consistently apply existing security controls.

CrowdStrike Tailors Adversary Intelligence to Customer Environments

A new release of CrowdStrike Falcon Adversary Intelligence delivers automatically prioritized threat intelligence tailored to each unique customer environment. By surfacing the right intelligence at the right time, this update enhances SOC workflows by enabling faster triage, deeper investigations, and more confident response. Today’s organizations understand threat intelligence is critical to stay ahead of adversaries, but many struggle to determine which threats matter most and how to act on them.

How CrowdStrike Secures AI Agents Across SaaS Environments

AI agents are being rapidly embedded into the SaaS ecosystem to streamline operations, trigger complex workflows, and interact with sensitive data and systems. From automating calendar updates to executing code and accessing cloud data stores, they are becoming integral to business processes. But with this integration comes risk. AI agents are often quickly deployed across SaaS environments by employees, without centralized tools to govern them.

AI vs. AI: The Race Between Adversarial and Defensive Intelligence

The AI battleground is here. Adversaries are weaponizing AI to launch attacks with unprecedented scale, speed, and effectiveness. In response, defenders are turning to AI as an analyst force-multiplier, using it to offload repetitive tasks, accelerate decision-making, and scale expertise across the SOC.

CrowdStrike 2025 Threat Hunting Report: AI Becomes a Weapon and a Target

Today’s enterprising adversaries are weaponizing AI to scale operations, accelerate attacks, and target the autonomous AI agents quickly transforming modern businesses. The CrowdStrike 2025 Threat Hunting Report details this new chapter in the threat landscape. This year’s report, based on frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts, examines how threat actors are using AI to do more with less.

Cloud Intrusions Rise, eCrime Thrives, Governments Attacked: CrowdStrike 2025 Threat Hunting Report

In the first half of 2025 alone, cloud intrusions were up 136% compared to all of 2024. China was a big driver — CrowdStrike saw a 40% year-over-year surge in intrusions from suspected cloud-conscious China-nexus threat actors. In the government sector, interactive intrusions increased 71%, and targeted intrusion activity jumped 185%.