January 2023 Summaries
10 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CrowdStrike has identified a sophisticated technique employed by threat actors to maintain persistence within AWS environments using federated sessions. This method involves exploiting the AWS Security Token Service (STS) to create temporary credentials that outlast the revocation of original IAM user credentials. By using the sts:GetFederationToken API call, attackers can generate federated sessions that inherit permissions from compromised IAM users, allowing them to perform actions even after the base user's API keys are deactivated. The federated sessions persist until they expire, unless the permissions of the base IAM user are explicitly overridden or reduced. CrowdStrike recommends using an explicit deny-all IAM policy or a Service Control Policy (SCP) to effectively revoke the permissions of such federated sessions. This persistence technique highlights the need for organizations to adopt best practices such as minimizing the use of long-lived credentials and applying robust policy controls to prevent unauthorized access and privilege escalation within cloud environments.
Jan 30, 2023
3,950 words in the original blog post.
CrowdStrike highlights the growing cybersecurity challenges faced by small and medium-sized businesses (SMBs), which are increasingly targeted by cybercriminals due to their limited security resources. The text details how SMBs, particularly in sectors like not-for-profit and transportation, are vulnerable to high-severity attacks due to outdated software, limited budgets, and lack of trained IT staff. These businesses often become targets not only for direct financial exploitation but also as weak links in supply chains that provide access to larger organizations. Despite these vulnerabilities, SMBs are advised to enhance their cybersecurity practices, such as adopting strong password policies, multi-factor authentication, and robust cybersecurity solutions like CrowdStrike Falcon. The text emphasizes the importance of SMBs utilizing advanced cybersecurity tools and services to prevent and respond to cyber threats effectively, highlighting CrowdStrike's offerings that include AI-driven protection, behavioral blocking, and comprehensive monitoring to safeguard SMBs from a wide range of cyber threats.
Jan 29, 2023
2,797 words in the original blog post.
The text highlights the cybersecurity landscape in 2025, emphasizing CrowdStrike's prominent role and achievements, such as being named a leader in various industry assessments like The Forrester Wave and IDC MarketScape. It details the challenges posed by data protection policies, especially data localization, which could undermine global cybersecurity practices necessary for effective threat detection and response. The narrative underscores the importance of using advanced cybersecurity measures like endpoint detection, zero trust identity protection, and AI-driven solutions to combat evolving threats, particularly those that are identity-driven or malware-free. With the backdrop of global regulatory environments and ongoing policy debates, the text advocates for harmonized cybersecurity requirements to ensure both compliance and robust data protection, while recognizing the critical role of international data flows in modern IT infrastructure.
Jan 27, 2023
2,110 words in the original blog post.
CrowdStrike's focus on securing PostgreSQL, a widely-used open-source relational database management system, highlights the critical importance of preventing misconfigurations that could allow cryptojacking attacks. PostgreSQL's robust capabilities make it a target for threat actors who exploit weak authentication settings, such as "trust" authentication, which allows access without a password. These vulnerabilities enable attackers to execute unauthorized commands to mine cryptocurrency or gain further access to cloud and Kubernetes environments. CrowdStrike emphasizes using their Falcon platform to detect and prevent such threats through comprehensive cloud security measures, including runtime protection, monitoring, and proactive assessments. The platform helps safeguard cloud infrastructures by addressing vulnerabilities and misconfigurations, thereby protecting against various threat actors including cryptojacking groups, eCrime organizations, and nation-state attackers. Implementing best practices for securing PostgreSQL, including strong passwords, proper authentication, and regular monitoring, is vital for maintaining a secure infrastructure.
Jan 26, 2023
3,426 words in the original blog post.
CrowdStrike, a leading cybersecurity company, has been actively enhancing its security capabilities across various domains, including AI, cloud, endpoint security, and identity protection. Their strategic partnerships, notably with Zscaler, have resulted in a seamless integration that provides comprehensive extended detection and response (XDR) solutions, offering robust visibility and response capabilities across enterprises. CrowdStrike's advancements include innovations in threat intelligence with the introduction of Threat AI, enhancements in data protection to prevent AI data leaks, and next-gen identity security innovations. They have also been recognized as leaders in multiple industry reports, reflecting their commitment to providing cutting-edge cybersecurity solutions. Additionally, CrowdStrike's Falcon platform continues to evolve, offering features like risk-based patching and a unified command console to streamline threat detection and response, underscoring their role in driving forward the cybersecurity landscape.
Jan 20, 2023
1,772 words in the original blog post.
CrowdStrike's blog discusses various aspects of cybersecurity, highlighting the company's advancements in AI security, threat intelligence, and cloud protections. The blog emphasizes CrowdStrike's innovative solutions like the Falcon Cloud Workload Protection, which helps prevent container escapes by addressing kernel vulnerabilities such as CVE-2021-3490. It explains how eBPF subsystem vulnerabilities in the Linux kernel can be exploited for privilege escalation and container escapes, outlining the technical methods and mitigations to prevent such attacks. The blog also mentions CrowdStrike's role in advancing next-gen identity security and its recognition as a leader in several cybersecurity market reports. Additionally, it covers the importance of maintaining robust security practices in cloud and container environments and offers resources like threat intelligence briefings and platform demonstrations to enhance organizational security readiness.
Jan 18, 2023
3,447 words in the original blog post.
CrowdStrike's blog discusses various developments and strategies in cybersecurity, emphasizing the importance of proactive threat hunting and advanced security measures. Key highlights include the introduction of Threat AI, the first agentic threat intelligence system, and innovations in identity security, data protection, and AI security services. The blog also details the use of tools like ngrok, ProxyChains, Plink, and HTRAN by adversaries to bypass network defenses and establish covert communications. CrowdStrike's Falcon OverWatch team actively monitors these threats, providing insights and recommendations to enhance security resilience. Additionally, the blog underscores CrowdStrike's leadership and recognition in the cybersecurity space through various accolades, such as being named a leader in the IDC MarketScape and Forrester Wave reports.
Jan 17, 2023
2,658 words in the original blog post.
The text provides an overview of CrowdStrike's cybersecurity efforts, highlighting its role as a leader in protecting small and medium-sized businesses (SMBs) from advanced cyber threats. It mentions the company's recognition in various industry reports, such as The Forrester Wave and IDC MarketScape, and details how CrowdStrike's technologies, like its Falcon platform, effectively address security challenges such as ransomware and identity-based attacks. A TechValidate survey of CrowdStrike's SMB customers reveals that the platform improves security operations efficiency, reduces the need for extensive security staffing, and offers robust protection with minimal false positives. The narrative underscores CrowdStrike's commitment to providing innovative and trusted cybersecurity solutions, which are essential for SMBs facing limited resources and increasing cyber threats. Additionally, the text highlights a special offer for SMBs to access CrowdStrike's services at a discounted rate, emphasizing the importance of accessible and reliable cybersecurity solutions for smaller organizations.
Jan 15, 2023
2,062 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity sectors, including cloud workload protection, identity security, and managed detection and response services. The company has introduced several innovations, such as Falcon Cloud Security for AI development protection and unified data protection to prevent GenAI data leaks. CrowdStrike's advancements also include integrating AI and machine learning to enhance security measures and collaborating with AI leaders to secure enterprise AI applications. Additionally, the company has been proactive in vulnerability management, offering solutions like risk-based patching and maintaining support for Windows 8.1 despite its end of support from Microsoft. CrowdStrike's efforts are underscored by its achievements in industry recognition and partnerships, demonstrating its commitment to advancing cybersecurity across various domains.
Jan 11, 2023
2,223 words in the original blog post.
CrowdStrike's recent activities and innovations focus on addressing advanced cybersecurity threats, particularly those targeting the telecom and business process outsourcing sectors. They highlight the persistent challenges posed by tactics such as "Bring Your Own Vulnerable Driver" (BYOVD), which exploit deficiencies in Windows security to bypass protections. Their Falcon platform effectively prevents these threats using machine learning and proactive threat intelligence, demonstrating the importance of a defense-in-depth approach. Additionally, CrowdStrike emphasizes the need for organizations to prioritize patching vulnerable drivers and leveraging advanced security features like Hypervisor-Protected Code Integrity (HVCI) to protect against sophisticated cyber adversaries. The company's continued advancements include improved identity security, AI integration, and strategic acquisitions to enhance its security offerings, underscoring its leadership in the cybersecurity domain.
Jan 10, 2023
2,637 words in the original blog post.