CrowdStrike

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor 2026-09-09 at 12:04 By Zeljka Zorz September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing […]

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor Read More »

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits 2026-09-07 at 15:15 By Ionut Arghire The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Read More »

Global sinkhole operation ends Sality botnet’s 23-year run

Global sinkhole operation ends Sality botnet’s 23-year run 2026-09-02 at 11:56 By Sinisa Markovic Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation […]

Global sinkhole operation ends Sality botnet’s 23-year run Read More »

Vulnerabilities Patched in CrowdStrike, Tenable Products

Vulnerabilities Patched in CrowdStrike, Tenable Products 2026-04-24 at 13:17 By Eduard Kovacs CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw. The post Vulnerabilities Patched in CrowdStrike, Tenable Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Patched in CrowdStrike, Tenable Products Read More »

Investor Lawsuit Over CrowdStrike Outage Dismissed

Investor Lawsuit Over CrowdStrike Outage Dismissed 2026-01-14 at 19:20 By Eduard Kovacs A judge has ruled that the plaintiffs failed to demonstrate intent to defraud investors.  The post Investor Lawsuit Over CrowdStrike Outage Dismissed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Investor Lawsuit Over CrowdStrike Outage Dismissed Read More »

CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million

CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million 2026-01-13 at 23:15 By Mike Lennon News of the move to acquire Seraphic comes less than a week after CrowdStrike announced an agreement to acquire identity security startup SGNL for $740 million. The post CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million appeared […]

CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million Read More »

CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash

CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash 2026-01-08 at 17:56 By Mike Lennon The deal aims to bolster CrowdStrike’s Falcon platform with “continuous identity” protection to secure human and AI-driven access in real-time. The post CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash appeared first on […]

CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash Read More »

CrowdStrike Insider Helped Hackers Falsely Claim System Breach

CrowdStrike Insider Helped Hackers Falsely Claim System Breach 2025-11-24 at 17:33 By Ionut Arghire The company has confirmed that it terminated an insider who shared screenshots of his computer with cybercriminals. The post CrowdStrike Insider Helped Hackers Falsely Claim System Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CrowdStrike Insider Helped Hackers Falsely Claim System Breach Read More »

F5 data breach: “Nation-state” attackers stole BIG-IP source code, vulnerability info

F5 data breach: “Nation-state” attackers stole BIG-IP source code, vulnerability info 2025-10-15 at 18:39 By Zeljka Zorz US tech company F5 has suffered a breach, and the attackers made off with source code of and vulnerability information related to its BIG-IP family of networking and security products, the company confirmed today. BIG-IP vulnerabilities are often […]

F5 data breach: “Nation-state” attackers stole BIG-IP source code, vulnerability info Read More »

CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry

CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry 2025-08-28 at 15:09 By SecurityWeek News CrowdStrike says the acquisition will bring valuable technology to enhance its Falcon Next-Gen SIEM. The post CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry appeared first on SecurityWeek. This article is an excerpt […]

CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry Read More »

Fake macOS help sites push Shamos infostealer via ClickFix technique

Fake macOS help sites push Shamos infostealer via ClickFix technique 2025-08-25 at 15:23 By Zeljka Zorz Criminals are taking advantage of macOS users’ need to resolve technical issues to get them to infect their machines with the Shamos infostealer, Crowdstrike researchers have warned. To prevent macOS security features from blocking the installation, the malware peddlers […]

Fake macOS help sites push Shamos infostealer via ClickFix technique Read More »

China-linked Murky Panda targets and moves laterally through cloud services

China-linked Murky Panda targets and moves laterally through cloud services 2025-08-22 at 17:33 By Zeljka Zorz In its recently released 2025 Threat Hunting Report, Crowdstrike pointed out an interesting trend: a 136% surge in cloud intrusions. A good chunk of this surge is due to “China-nexus adversaries”, Murky Panda (aka Silk Typhoon) among them. Murky […]

China-linked Murky Panda targets and moves laterally through cloud services Read More »

Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage 

Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage  2025-06-27 at 14:50 By Eduard Kovacs Microsoft is preparing a private preview of new Windows endpoint security platform capabilities to help antimalware vendors create solutions that run outside the kernel. The post Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage  appeared […]

Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage  Read More »

Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names

Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names 2025-06-03 at 11:33 By Eduard Kovacs Microsoft and CrowdStrike are running a project that aims to align threat actor names, and Google and Palo Alto Networks will also contribute. The post Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names appeared first on SecurityWeek. This article […]

Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names Read More »

DanaBot botnet disrupted, QakBot leader indicted

DanaBot botnet disrupted, QakBot leader indicted 2025-05-23 at 14:17 By Zeljka Zorz Operation Endgame, mounted by law enforcement and judicial authorities from the US, Canada and the EU, continues to deliver positive results by disrupting the DanaBot botnet and indicting the leaders of both the DanaBot and Qakbot Malware-as-a-Service operations. Operation Endgame 2.0 Coordinated by […]

DanaBot botnet disrupted, QakBot leader indicted Read More »

Wave of tech layoffs leads to more job scams

Wave of tech layoffs leads to more job scams 2025-05-08 at 08:06 By Sinisa Markovic The tech industry is experiencing significant layoffs, leaving thousands of IT and cybersecurity professionals in search of new employment opportunities. Unfortunately, as these individuals search for new opportunities, scammers are actively preying on them. Losing a job, especially when you […]

Wave of tech layoffs leads to more job scams Read More »

CrowdStrike Plans Layoffs to Pursue $10B ARR Target

CrowdStrike Plans Layoffs to Pursue $10B ARR Target 2025-05-07 at 19:03 By SecurityWeek News CrowdStrike said the planned cuts will affect approximately 500 employees and will span the first half of fiscal 2026. The post CrowdStrike Plans Layoffs to Pursue $10B ARR Target appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

CrowdStrike Plans Layoffs to Pursue $10B ARR Target Read More »

26 New Threat Groups Spotted in 2024: CrowdStrike

26 New Threat Groups Spotted in 2024: CrowdStrike 2025-02-27 at 21:03 By Eduard Kovacs CrowdStrike has published its 2025 Global
Threat Report, which warns of faster breakout time and an increase in Chinese activity.  The post 26 New Threat Groups Spotted in 2024: CrowdStrike appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

26 New Threat Groups Spotted in 2024: CrowdStrike Read More »

Job-seeking devs targeted with fake CrowdStrike offer via email

Job-seeking devs targeted with fake CrowdStrike offer via email 2025-01-10 at 14:33 By Zeljka Zorz Cryptojackers are impersonating Crowdstrike via email to get developers to unwittingly install the XMRig cryptocurrency miner on their Windows PC, the company has warned. The email Crowdstrike has a web page where job hunters can see which positions are open […]

Job-seeking devs targeted with fake CrowdStrike offer via email Read More »

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287) 2024-11-19 at 12:48 By Zeljka Zorz Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers. About CVE-2024-21287 Oracle Agile PLM Framework is an enterprise product lifecycle management solution […]

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287) Read More »

Scroll to Top