Context, Official Statements, and Possible Solutions for Today’s CrowdStrike BSOD – Windows Host Outage
Before we begin our planned weekly incident analysis, the entire Adversary Pursuit Group and everyone else here at Blackpoint Cyber want to extend good energy to all those IT teams pulling all-nighters for the next few days to get rid of the Blue Screens of Death (BSOD) currently impacting Windows hosts of the flawed Falcon content update — as well as the teams at CrowdStrike and Windows currently pulling together to fix the rollout for all Falcon customers.
As MacKensie Brown, VP of the APG, said today while waiting for her flight at an impacted airport:
While the fix is somewhat simple (albeit extremely manual for recovery), IT operations will be working full throttle. Our thoughts are with those teams, and if anyone needs help, please reach out.
For more information on today’s outage (updated July 20, 2024):
- “Context Around the CrowdStrike July 2024 Outage” (Blackpoint)
- “Statement on Falcon Content Update for Windows Hosts” (CrowdStrike)
- APG Principal Researcher Robel Campbell’s initial analysis
- “Technical Details: Falcon Content Update for Windows Hosts” (CrowdStrike)
- APG Threat Intelligence Director Nick Hyatt’s warning on opportunistic phishing attacks
- Possible bootable USB drive fix to CrowdStrike BSOD with Bitlocker support (u/denismcapple & Brandon Garrett)
- “The CrowdStrike fail and next global IT meltdown already in the making” (Kevin Williams for CNBC)
Now, let’s get back to your regularly scheduled Blackpoint Active SOC incident analysis!