|
By Daniel Bernard
Critical infrastructure is where cyber risk becomes real-world risk. The environments powering energy, water, manufacturing, and transportation are among the most complex to defend as they often combine decades-old operational technology (OT) with modern IT. Downtime is not an option, and patching isn’t always possible. Now, AI is raising the stakes. Adversaries are using AI to move faster and operate at greater scale, compressing the time defenders have to respond to attacks.
|
By Atul Tulshibagwale
Zero Trust continues to present an often-overlooked challenge: keeping access decisions accurate as the real-world conditions behind them change. Over the past decade, AI, cloud transformation, mobile access, and remote work have challenged existing security paradigms at a fundamental level.
|
By Ashley Campion
CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.
CrowdStrike has been named a Leader in the 2026 IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises Vendor Assessment. We believe this recognition reflects the strength of the CrowdStrike Falcon platform and the proven endpoint capabilities CrowdStrike brings into the AI era: industry-leading protection at scale, consistent analyst recognition, measurable business value, and the trust of customers globally.
Modern frontier AI models deploy safety classifiers. These are second AI models that sit between the user and the frontier model, evaluating every request in real time. If a request is flagged as harmful, the classifier blocks it before the model can respond. Significant investment and safety model expertise have made these classifiers effective. Anticipating how adversaries circumvent these systems is a security problem that requires different expertise.
|
By Dana Larson
For many organizations, Microsoft 365 environments are essential to data security strategy. Their strategic plans live in SharePoint; their employee records and customer data are stored in OneDrive. Teams use these tools to collaborate on projects every day, and increasingly, AI tools like Microsoft Copilot can access the information they rely on.
|
By Jason Williams
Two forces are reshaping modern cloud posture management: context and AI. Context gives security teams the business insight to understand risk. AI helps them turn that insight into faster, more informed action. CrowdStrike Falcon Cloud Security is advancing both. New third-party application insights map the external services cloud-native applications depend on, helping customers assess the risk those dependencies introduce.
|
By Karan Sondhi
CISA has called SIEM-as-a-service (SIEMaaS) “the Rosetta Stone” for visibility for good reason. Federal defenders need to see what is happening across increasingly complex environments, understand what matters, and turn that context into action before an adversary achieves its objective.
|
By Hananel Livneh
Consider this hypothetical scenario: An employee tries to join what looks like a routine video meeting. The page loads, but instead of the meeting, they see an error message along with a helpful fix: Copy the provided command, open the Windows Run dialog, paste it, and press Enter. The meeting never starts. The command does something else entirely. This is ClickFix, a social engineering technique that turns the victim into the mechanism for executing an attack.
|
By Bartley Richardson
AI agents are already operating across the enterprise. As they become more autonomous in accessing data, using credentials, executing code, and acting across critical systems, the security boundary is changing with them. The question is no longer whether enterprises will adopt agents. It's how they give agents greater autonomy without giving up control.
|
By CrowdStrike
Proactive security starts with understanding the environment before an attacker can take advantage of it. In this demo, see how the CrowdStrike Falcon platform brings together proactive telemetry and context across endpoint, cloud, identity, network, applications, SaaS, and more to build a connected view of risk.
|
By CrowdStrike
See CrowdStrike Falcon Data Security for SaaS in action and learn how to discover, classify, and protect sensitive data across Microsoft 365. See how security teams can identify sensitive data in SharePoint and OneDrive, prioritize exposure, automatically apply Microsoft Sensitivity Labels, reduce unintended Microsoft Copilot exposure, and extend protection with just-in-time access.
|
By CrowdStrike
CrowdStrike's Falcon for XIoT addresses challenges in managing complex industrial and clinical environments by providing visibility into operational assets. The solution helps teams prioritize vulnerabilities based on operational impact rather than severity alone, ensuring safe decisions while minimizing interruptions. Through a detailed investigation process, users can assess asset profiles, validate exposures, and implement controlled responses tailored to specific risks. This approach optimizes asset management and enhances safety in both operational technology (OT) and clinical settings.
|
By CrowdStrike
Adversaries are targeting the browser — hijacking sessions, stealing credentials, and exploiting gaps traditional tools can’t see.
|
By CrowdStrike
Adversaries are targeting the browser — hijacking sessions, stealing credentials, and exploiting gaps traditional tools can’t see. Watch how CrowdStrike's Falcon Seraphic Enterprise Browser delivers zero trust runtime protection directly in the browser, combining secure access with deep, real-time visibility and control over user activity.
|
By CrowdStrike
Adversaries are targeting the browser — hijacking sessions, stealing credentials, and exploiting gaps traditional tools can’t see. Watch how CrowdStrike's Falcon Seraphic Enterprise Browser delivers zero trust runtime protection directly in the browser, combining secure access with deep, real-time visibility and control over user activity.
|
By CrowdStrike
Adversaries are moving faster than ever, exploiting vulnerabilities soon after they’re discovered. As frontier AI accelerates reconnaissance and exploit development, Security and IT teams need to identify endpoint risk and act before exposure becomes compromise. Meet Falcon for IT, a solution that helps teams uncover emerging risk, establish operational control, and accelerate targeted remediation across the endpoint fleet.
|
By CrowdStrike
Work no longer happens inside a clearly defined perimeter. It happens in the browser, where users access SaaS applications, private resources, sensitive data, and AI tools from managed devices, personal devices, and contractor environments. Traditional security controls were designed to inspect traffic at the network edge. But they often lack visibility into what happens inside the browser after access is granted, including copy and paste, uploads, downloads, screenshots, risky extensions, session activity, and AI.
|
By CrowdStrike
How do we secure the future of AI? At Fal.Con 2026, CrowdStrike introduced new AI security innovations, including CrowdStrike Falcon Guardian and CrowdStrike SafeMind, built with NVIDIA.
|
By CrowdStrike
Over the past several decades, China’s five-year plan has provided a roadmap to the country's innovation and economic growth. It details what China is interested in, where technology is evolving, and what it plans to target, including the highest-priority verticals. “It’s their shopping list,” as Adam puts it. His team does a deep analysis on these plans, including information published adjacent to it and the discrepancies across various languages.
|
By CrowdStrike
Visibility in the cloud is an important but difficult problem to tackle. It differs among cloud providers, and each one has its own positive and negative aspects. This guide covers some of the logging and visibility options that Amazon Web Services (AWS) and Google Cloud Platform (GCP) offer, and highlights their blind spots and how to eliminate them.
|
By CrowdStrike
Since a majority of the breaches are credential based, securing your multi-directory identity store - Microsoft Active Directory (AD) and Azure AD - is critical to protecting your organization from adversaries launching ransomware and supply chain attacks. Your security and IAM teams are concerned about securing AD and maintaining AD hygiene - and they need to be in sync, for example, to ensure that legacy and deprecated protocols like NTLMv1 are not being used and that the right security controls are in place to prevent breaches in real time.
|
By CrowdStrike
You have to secure your workforce identities immediately, to protect your organization from modern attacks like ransomware and supply chain threats. Your environment could be just Microsoft Active Directory (AD), or a hybrid identity store with AD and Azure AD, and it's important to have a holistic view of the directories and a frictionless approach to securing them. If you're considering Microsoft to secure your identities and identity store (AD and Azure Active Directory), you should ask these five questions.
|
By CrowdStrike
Learn about how to strengthen and modernize your agency's security protection, detection and remediation with Zero Trust. This white paper explains the unique risk factors federal agencies face, what a superior Zero Trust framework includes, and how cloud and endpoint security can help modernize federal security from the endpoint to the application.
|
By CrowdStrike
Cloud adoption remains a key driver for digital transformation and growth for today's businesses, helping them deliver applications and services to customers with the speed and scalability that only the cloud can provide. Enabling them to do so safely is a critical objective for any enterprise IT security team.
|
By CrowdStrike
Network segmentation has been around for a while and is one of the core elements in the NIST SP 800-207 Zero Trust framework. Although network segmentation reduces the attack surface, this strategy does not protect against adversary techniques and tactics in the identity phases in the kill chain. The method of segmentation that provides the most risk reduction, at reduced cost and operational complexity, is identity segmentation.
- October 2026 (12)
- September 2026 (22)
- August 2026 (12)
- July 2026 (22)
- June 2026 (27)
- May 2026 (34)
- April 2026 (47)
- March 2026 (32)
- February 2026 (33)
- January 2026 (18)
- December 2025 (25)
- November 2025 (17)
- October 2025 (21)
- September 2025 (23)
- August 2025 (27)
- July 2025 (34)
- June 2025 (20)
- May 2025 (20)
- April 2025 (24)
- March 2025 (31)
- February 2025 (18)
- January 2025 (14)
- December 2024 (25)
- November 2024 (8)
- October 2024 (26)
- September 2024 (8)
- August 2024 (6)
- July 2024 (17)
- June 2024 (20)
- May 2024 (17)
- April 2024 (17)
- March 2024 (16)
- February 2024 (21)
- January 2024 (11)
- December 2023 (11)
- November 2023 (21)
- October 2023 (19)
- September 2023 (18)
- August 2023 (21)
- July 2023 (7)
- June 2023 (15)
- May 2023 (14)
- April 2023 (15)
- March 2023 (16)
- February 2023 (13)
- January 2023 (19)
- December 2022 (29)
- November 2022 (19)
- October 2022 (26)
- September 2022 (22)
- August 2022 (14)
- July 2022 (8)
- June 2022 (23)
- May 2022 (17)
- April 2022 (20)
- March 2022 (34)
- February 2022 (20)
- January 2022 (18)
- December 2021 (27)
- November 2021 (5)
- September 2021 (1)
- August 2021 (6)
- July 2021 (5)
CrowdStrike protects the people, processes and technologies that drive modern enterprise. A single agent solution to stop breaches, ransomware, and cyber attacks—powered by world-class security expertise and deep industry experience.
Many of the world’s largest organizations already put their trust in CrowdStrike, including three of the 10 largest global companies by revenue, five of the 10 largest financial institutions, three of the top 10 health care providers, and three of the top 10 energy companies.
A Radical New Approach Proven To Stop Breaches:
- Cloud Native: Eliminates complexity and simplifies deployment to drive down operational costs.
- AI Powered: Harnesses the power of big data and artificial intelligence to empower your team with instant visibility.
- Single Agent: Delivers everything you need to stop breaches — providing maximum effectiveness on day one.
One platform. Every industry. Superior protection.