Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CrowdStrike Accelerates Real-Time Data Classification with On-Device AI

Modern data security depends on understanding sensitive data as it is created, accessed, and moved in real time directly on the endpoint. In addition to identifying predefined patterns such as credit card numbers or Social Security numbers, organizations must protect unstructured information including documents, chat logs, support tickets, AI prompts, medical records, and free-text fields.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software.

CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day.

CrowdStrike Delivers the Next Evolution of the Agentic SOC

The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time.

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.

CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches. This shift demands a new approach to AI security.

CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar: Cloud Workload Protection Platforms

We are proud to announce that Frost & Sullivan has named CrowdStrike as the strongest overall leader in the Frost Radar: Cloud Workload Protection Platforms, 2026. CrowdStrike earned the highest scores in Innovation and Growth among 18 companies benchmarked from a field of more than 45 qualified participants. Today’s cloud attacks are designed to hide in plain sight.

Benchmaxxing: When the Benchmark Becomes the Target

Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space.

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

VMware ESX systems are a recurring target in ransomware campaigns. Threat groups including SCATTERED SPIDER, BlackBasta, Royal (aka BlackSuit), Akira, and the ESX-focused ransomware as a service (RaaS) platform shinysp1d3r have demonstrated that once an adversary reaches the hypervisor layer, they can rapidly encrypt virtual machines, disable logging, and cripple an entire data center.