Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Falcon AIDR: Copilot Studio, Claude Code, and Browser-Based AI Coverage Enhancements

AI adoption is expanding into agents, developer workflows, and browser-based experiences, creating new blind spots where security teams need visibility, context, and control. See how CrowdStrike Falcon extends AI security coverage across Microsoft Copilot Studio, Claude Code, and the Falcon Browser Extension. Learn how Falcon helps security teams evaluate agent tool use, enforce allow or block policy decisions, inspect prompts and responses for risks like prompt injection, sensitive data, and malicious content, and enrich investigations with endpoint identity context from the Falcon sensor.

Securing AI at the Endpoint with CrowdStrike Falcon

AI is moving beyond browser tabs and SaaS apps into agents, local models, MCP servers, IDE extensions, and AI development frameworks running directly on the endpoint. These tools can access files, source code, credentials, and enterprise data with user-level privileges, creating new blind spots for security and IT teams. In this demo, see how CrowdStrike Falcon helps close the endpoint AI visibility gap by discovering, governing, and defending AI usage across the enterprise.

Falcon AIDR Now Protects Copilot Studio Agents and Claude Code

Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.

Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud

Every change in a cloud environment creates new security decisions. A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release introduces new cloud interactions. A Kubernetes cluster needs protection before it goes into production. Individually, these are routine tasks. Together, they create growing operational friction that makes cloud security harder to scale.

Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats

Organizations face a relentless stream of emerging threats, from zero-day exploits to rapidly evolving adversary tactics. They need protection that keeps pace with this changing landscape without adding operational complexity. The key challenge here is turning threat intelligence into production-ready detections before attackers can gain an advantage.

Lightboard Lab: Why Browser Security

Securing the browser is no longer optional, but not every approach delivers the same level of protection, flexibility, or user experience. Remote browser isolation, VDI, dedicated secure browsers, and browser extensions can each address part of the problem. But they may also introduce latency, force users into unfamiliar workflows, create patching gaps, or lack visibility into the browser runtime where sessions, tokens, data, and attacks converge.

Defeat Frontier AI Attacks: Charlotte AI AgentWorks Meets Falcon for IT

Frontier AI has armed adversaries with unprecedented speed, finding and exploiting vulnerabilities faster than humans can respond. To keep pace, defenders need agentic AI operating on defense. In this demo, see how a Frontier AI Exploitation Defense Agent in Charlotte AI AgentWorks identifies and prioritizes critical risk, then hands off to Falcon for IT Risk-Based Patch Management for controlled remediation, all within the CrowdStrike Falcon platform.

AIDR: Defining the Next Era of Cybersecurity

AI is changing how work gets done. It is also creating a new attack surface. Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecting, investigating, and responding to threats targeting and originating from AI systems, agents, and autonomous workflows. In this virtual event, you’ll learn.

CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security

AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders need the ability to inspect, test, adapt, and secure the systems they depend on.

FalconID: Third-Party Passkeys

Passwords and traditional MFA remain common targets for phishing and credential theft. FalconID extends phishing-resistant, FIDO2-based passkeys to third-party applications, enabling secure, passwordless authentication across platforms like Entra ID, Okta, GitHub, and Salesforce. Passkeys are device-bound, centrally managed through the Falcon console, and continuously protected by Falcon security signals—allowing organizations to revoke access instantly when risk changes.

CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04

On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, which transforms federal vulnerability management by shifting agencies from static CVSS-based patching to a dynamic, risk-based model. This supersedes BOD 19-02 and BOD 22-01. Agencies must now prioritize remediation using four key factors: public asset exposure, KEV catalog status, exploit automatability, and technical impact (partial vs. total control).

Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks

In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows.

Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense

Frontier AI is fundamentally changing the pace of cybersecurity. For defenders and adversaries alike, it compresses the time required to discover vulnerabilities, assess exploitability, and act. AI models can reason across entire codebases, identify complex vulnerability chains, and generate exploit paths at a speed and scale that was previously impossible. That's a breakthrough for defenders, but it's also a preview of how quickly adversaries will evolve.

AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity

Every foundational shift in computing has created a new security category. The internet created network security, the rise of workstations created the need for endpoint detection and response (EDR), and cloud computing created the need for cloud security. Each technology transition has moved faster than the one before it. None has moved faster than AI.

SaaS Security Threats to Worry About, with Salesforce's Kelly McCracken

Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendors, the most underappreciated SaaS misconfigurations, and what the future of the shared responsibility model looks like.

Why AI Governance Without Guardrails Is Theater

AI governance is a key enterprise concern. Organizations are assembling councils, publishing principles, rolling out “approved AI tools” lists, and asking employees to opt in to acceptable use policies. In most enterprises, however, the reality is that AI is already widely embedded in employees' daily work, often outside sanctioned channels and oversight. The visibility and control mechanisms needed to govern AI use are immature or nonexistent.

Falcon Secure Access Sets the Standard for Zero Trust Browser Security

The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal web apps, admin consoles, collaboration tools, and AI services from anywhere, often across a mix of managed, unmanaged, and personally owned devices. As they do, adversaries are increasingly targeting the browser session itself.

CrowdStrike Uncovers New Prompt Injection Techniques

Prompt injection is among the defining security challenges of the AI era. As organizations move from chatbots to AI agents, adversaries are finding more ways to manipulate the language, context, and data these systems trust. With the rise of powerful AI agents that can crawl webpages, access file stores, and even write shell commands, indirect prompt injection has emerged as a critical threat vector.

How AI-leading Security Teams Are Building the Agentic SOC

AI-enabled attacks move faster than human analysts can track, at a scale that traditional SOCs weren’t designed to withstand. eCrime breakout times collapsed to 29 minutes on average in 2025, with the fastest clocked at 27 seconds. The rise of frontier AI models is expected to compress the time between vulnerability discovery and exploitation, intensifying pressure on SOC teams. Defending against AI-accelerated adversaries requires a new operating model.