Global Outage: CrowdStrike Update Causes Widespread Disruptions

CrowdStrike’s recent software update caused a significant global outage, affecting banks, airlines, hospitals, and government offices. The faulty code in the update led to 'blue screens of death' on computers, forcing a manual fix. Experts noted inadequate quality checks before deployment as the primary cause.

Global Outage: CrowdStrike Update Causes Widespread Disruptions
AI Generated Representative Image

Security experts revealed that CrowdStrike's routine cybersecurity software update, which caused global computer system crashes on Friday, seemingly lacked adequate quality checks before its release. The latest Falcon sensor software version aimed to enhance system security against hacking by updating threat defenses. However, faulty code in the update files led to one of the most extensive tech outages in recent history for companies using Microsoft's Windows OS.

Global banks, airlines, hospitals, and government offices experienced disruptions. Although CrowdStrike issued guidance to fix the affected systems, experts highlighted that the rectification process would be time-consuming due to the need for manual code correction. Steve Cobb, Chief Security Officer at Security Scorecard, suggested the flawed file might have bypassed usual vetting procedures.

The issue quickly became evident post-update rollout, with users sharing images on social media of computers showing 'blue screens of death.' Security researcher Patrick Wardle identified the problematic code, which contained either configuration or signature data. Wardle noted that regular security product updates aim to protect against the latest threats, potentially explaining the insufficient testing of this update.

The frequency of updates likely contributed to the oversight, making it unclear how the faulty code passed undetected through quality checks. John Hammond, principal security researcher at Huntress Labs, recommended a more cautious, limited rollout approach to prevent such widespread issues. Similar incidents have previously affected other security firms like McAfee in 2010. However, the current situation underscores CrowdStrike’s market dominance, with over half of the Fortune 500 companies and key government agencies relying on its software.

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.