|
By Bartley Richardson
AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders need the ability to inspect, test, adapt, and secure the systems they depend on.
|
By Karan Sondhi
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, which transforms federal vulnerability management by shifting agencies from static CVSS-based patching to a dynamic, risk-based model. This supersedes BOD 19-02 and BOD 22-01. Agencies must now prioritize remediation using four key factors: public asset exposure, KEV catalog status, exploit automatability, and technical impact (partial vs. total control).
|
By John Prieto
In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows.
|
By Joel Spurlock
Frontier AI is fundamentally changing the pace of cybersecurity. For defenders and adversaries alike, it compresses the time required to discover vulnerabilities, assess exploitability, and act. AI models can reason across entire codebases, identify complex vulnerability chains, and generate exploit paths at a speed and scale that was previously impossible. That's a breakthrough for defenders, but it's also a preview of how quickly adversaries will evolve.
|
By CrowdStrike
Every foundational shift in computing has created a new security category. The internet created network security, the rise of workstations created the need for endpoint detection and response (EDR), and cloud computing created the need for cloud security. Each technology transition has moved faster than the one before it. None has moved faster than AI.
|
By CrowdStrike
AI governance is a key enterprise concern. Organizations are assembling councils, publishing principles, rolling out “approved AI tools” lists, and asking employees to opt in to acceptable use policies. In most enterprises, however, the reality is that AI is already widely embedded in employees' daily work, often outside sanctioned channels and oversight. The visibility and control mechanisms needed to govern AI use are immature or nonexistent.
|
By Hananel Livneh
The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal web apps, admin consoles, collaboration tools, and AI services from anywhere, often across a mix of managed, unmanaged, and personally owned devices. As they do, adversaries are increasingly targeting the browser session itself.
|
By David Keller
Prompt injection is among the defining security challenges of the AI era. As organizations move from chatbots to AI agents, adversaries are finding more ways to manipulate the language, context, and data these systems trust. With the rise of powerful AI agents that can crawl webpages, access file stores, and even write shell commands, indirect prompt injection has emerged as a critical threat vector.
AI-enabled attacks move faster than human analysts can track, at a scale that traditional SOCs weren’t designed to withstand. eCrime breakout times collapsed to 29 minutes on average in 2025, with the fastest clocked at 27 seconds. The rise of frontier AI models is expected to compress the time between vulnerability discovery and exploitation, intensifying pressure on SOC teams. Defending against AI-accelerated adversaries requires a new operating model.
|
By Hananel Livneh
The browser is the operating environment for modern work — it’s where employees access email, SaaS applications, collaboration tools, HR systems, finance platforms, customer data, developer resources and AI services. All of this activity makes the browser a high-value target for attackers because it sits between users, identities, applications, and sensitive enterprise data.
|
By CrowdStrike
AI is changing how work gets done. It is also creating a new attack surface. Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecting, investigating, and responding to threats targeting and originating from AI systems, agents, and autonomous workflows. In this virtual event, you’ll learn.
|
By CrowdStrike
Securing the browser is no longer optional, but not every approach delivers the same level of protection, flexibility, or user experience. Remote browser isolation, VDI, dedicated secure browsers, and browser extensions can each address part of the problem. But they may also introduce latency, force users into unfamiliar workflows, create patching gaps, or lack visibility into the browser runtime where sessions, tokens, data, and attacks converge.
|
By CrowdStrike
Adversaries are abusing the cloud-native you trust to blend in and remain undetected. See how Falcon Cloud Security detects adversary behavior in real time with Cloud Detection and Response (CDR).
|
By CrowdStrike
Passwords and traditional MFA remain common targets for phishing and credential theft. FalconID extends phishing-resistant, FIDO2-based passkeys to third-party applications, enabling secure, passwordless authentication across platforms like Entra ID, Okta, GitHub, and Salesforce. Passkeys are device-bound, centrally managed through the Falcon console, and continuously protected by Falcon security signals—allowing organizations to revoke access instantly when risk changes.
|
By CrowdStrike
Falcon Cloud Security helps security teams stop active attacks and eliminate the critical exposures that enable them - all from a single AI-native platform backed by industry-leading adversary intelligence.
|
By CrowdStrike
Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendors, the most underappreciated SaaS misconfigurations, and what the future of the shared responsibility model looks like.
|
By CrowdStrike
Falcon Cloud Security correlates cloud exposures into prioritized attack paths and enriches them with CrowdStrike adversary intelligence, helping teams focus on the risks most likely to be exploited across AWS, Azure, and Google Cloud. Subscribe and stay updated!
|
By CrowdStrike
Falcon Cloud Security correlates cloud exposures into prioritized attack paths and enriches them with CrowdStrike adversary intelligence, helping teams focus on the risks most likely to be exploited across AWS, Azure, and Google Cloud. Subscribe and stay updated!
|
By CrowdStrike
Today’s adversaries move at the speed of AI, so defenders need to reason, decide, and act faster across every stage of security operations. Meet Charlotte AI AgentWorks, a no-code agent builder that enables teams to create mission-ready AI agents directly inside the CrowdStrike Falcon platform.
|
By CrowdStrike
As adversaries use Frontier AI to discover, chain, and exploit vulnerabilities faster, security teams need to understand what is exploitable, where they are exposed, and how to reduce risk before attackers act. In this demo, see how Falcon Exposure Management helps teams operationalize CTEM across the attack surface. The walkthrough highlights continuous visibility across internal and external exposures, network vulnerabilities, applications, browser extensions, AI inventory, and attack paths.
|
By CrowdStrike
Visibility in the cloud is an important but difficult problem to tackle. It differs among cloud providers, and each one has its own positive and negative aspects. This guide covers some of the logging and visibility options that Amazon Web Services (AWS) and Google Cloud Platform (GCP) offer, and highlights their blind spots and how to eliminate them.
|
By CrowdStrike
Since a majority of the breaches are credential based, securing your multi-directory identity store - Microsoft Active Directory (AD) and Azure AD - is critical to protecting your organization from adversaries launching ransomware and supply chain attacks. Your security and IAM teams are concerned about securing AD and maintaining AD hygiene - and they need to be in sync, for example, to ensure that legacy and deprecated protocols like NTLMv1 are not being used and that the right security controls are in place to prevent breaches in real time.
|
By CrowdStrike
You have to secure your workforce identities immediately, to protect your organization from modern attacks like ransomware and supply chain threats. Your environment could be just Microsoft Active Directory (AD), or a hybrid identity store with AD and Azure AD, and it's important to have a holistic view of the directories and a frictionless approach to securing them. If you're considering Microsoft to secure your identities and identity store (AD and Azure Active Directory), you should ask these five questions.
|
By CrowdStrike
Learn about how to strengthen and modernize your agency's security protection, detection and remediation with Zero Trust. This white paper explains the unique risk factors federal agencies face, what a superior Zero Trust framework includes, and how cloud and endpoint security can help modernize federal security from the endpoint to the application.
|
By CrowdStrike
Network segmentation has been around for a while and is one of the core elements in the NIST SP 800-207 Zero Trust framework. Although network segmentation reduces the attack surface, this strategy does not protect against adversary techniques and tactics in the identity phases in the kill chain. The method of segmentation that provides the most risk reduction, at reduced cost and operational complexity, is identity segmentation.
|
By CrowdStrike
Cloud adoption remains a key driver for digital transformation and growth for today's businesses, helping them deliver applications and services to customers with the speed and scalability that only the cloud can provide. Enabling them to do so safely is a critical objective for any enterprise IT security team.
- July 2026 (15)
- June 2026 (27)
- May 2026 (34)
- April 2026 (47)
- March 2026 (32)
- February 2026 (33)
- January 2026 (18)
- December 2025 (25)
- November 2025 (17)
- October 2025 (21)
- September 2025 (23)
- August 2025 (27)
- July 2025 (34)
- June 2025 (20)
- May 2025 (20)
- April 2025 (24)
- March 2025 (31)
- February 2025 (18)
- January 2025 (14)
- December 2024 (25)
- November 2024 (8)
- October 2024 (26)
- September 2024 (8)
- August 2024 (6)
- July 2024 (17)
- June 2024 (20)
- May 2024 (17)
- April 2024 (17)
- March 2024 (16)
- February 2024 (21)
- January 2024 (11)
- December 2023 (11)
- November 2023 (21)
- October 2023 (19)
- September 2023 (18)
- August 2023 (21)
- July 2023 (7)
- June 2023 (15)
- May 2023 (14)
- April 2023 (15)
- March 2023 (16)
- February 2023 (13)
- January 2023 (19)
- December 2022 (29)
- November 2022 (19)
- October 2022 (26)
- September 2022 (22)
- August 2022 (14)
- July 2022 (8)
- June 2022 (23)
- May 2022 (17)
- April 2022 (20)
- March 2022 (34)
- February 2022 (20)
- January 2022 (18)
- December 2021 (27)
- November 2021 (5)
- September 2021 (1)
- August 2021 (6)
- July 2021 (5)
CrowdStrike protects the people, processes and technologies that drive modern enterprise. A single agent solution to stop breaches, ransomware, and cyber attacks—powered by world-class security expertise and deep industry experience.
Many of the world’s largest organizations already put their trust in CrowdStrike, including three of the 10 largest global companies by revenue, five of the 10 largest financial institutions, three of the top 10 health care providers, and three of the top 10 energy companies.
A Radical New Approach Proven To Stop Breaches:
- Cloud Native: Eliminates complexity and simplifies deployment to drive down operational costs.
- AI Powered: Harnesses the power of big data and artificial intelligence to empower your team with instant visibility.
- Single Agent: Delivers everything you need to stop breaches — providing maximum effectiveness on day one.
One platform. Every industry. Superior protection.