Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.

CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches. This shift demands a new approach to AI security.

CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar: Cloud Workload Protection Platforms

We are proud to announce that Frost & Sullivan has named CrowdStrike as the strongest overall leader in the Frost Radar: Cloud Workload Protection Platforms, 2026. CrowdStrike earned the highest scores in Innovation and Growth among 18 companies benchmarked from a field of more than 45 qualified participants. Today’s cloud attacks are designed to hide in plain sight.

Benchmaxxing: When the Benchmark Becomes the Target

Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space.

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

VMware ESX systems are a recurring target in ransomware campaigns. Threat groups including SCATTERED SPIDER, BlackBasta, Royal (aka BlackSuit), Akira, and the ESX-focused ransomware as a service (RaaS) platform shinysp1d3r have demonstrated that once an adversary reaches the hypervisor layer, they can rapidly encrypt virtual machines, disable logging, and cripple an entire data center.

Secure Agent Harness Execution: Preventing Escape

At CrowdStrike, we conduct extensive red-team testing of agentic systems using diverse models, tools, and adversarial evaluation harnesses designed to probe for containment failures. To date, none of our offensive agents have escaped their intended sandbox boundaries.

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates

The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them. Our frontline intelligence in this year’s report underscores this shift.

Falcon AIDR Now Protects Copilot Studio Agents and Claude Code

Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.

Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud

Every change in a cloud environment creates new security decisions. A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release introduces new cloud interactions. A Kubernetes cluster needs protection before it goes into production. Individually, these are routine tasks. Together, they create growing operational friction that makes cloud security harder to scale.

Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats

Organizations face a relentless stream of emerging threats, from zero-day exploits to rapidly evolving adversary tactics. They need protection that keeps pace with this changing landscape without adding operational complexity. The key challenge here is turning threat intelligence into production-ready detections before attackers can gain an advantage.