Home / Companies / Crowdstrike / Blog / August 2025

August 2025 Summaries

17 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
In 2025, CrowdStrike has been recognized as a leader in various cybersecurity domains, including incident response services and exposure management, while also announcing its strategic acquisition of Onum to enhance the real-time data capabilities of its Falcon platform. This move is aimed at transforming security operations by integrating Onum’s real-time telemetry pipeline management to optimize data flow, enabling faster and more precise threat detection and response. The acquisition highlights CrowdStrike’s commitment to leveraging advanced technologies, such as AI, to address the evolving threat landscape and data challenges faced by security teams. As legacy SIEM systems struggle with data overload and inefficiency, Onum’s architecture is set to deliver enriched telemetry and reduce costs, reinforcing CrowdStrike's mission to build a unified platform that effectively stops breaches.
Aug 27, 2025 2,018 words in the original blog post.
CrowdStrike has been recognized as a leader in the IDC MarketScape for Worldwide Incident Response Services in 2025, highlighting its expertise in delivering rapid and effective incident responses driven by the AI-native CrowdStrike Falcon® platform. This recognition underscores the growing necessity for swift and comprehensive incident response as cyber threats evolve, with adversaries increasingly utilizing AI to enhance their attacks. CrowdStrike's approach combines industry-leading expertise with AI innovation, offering an integrated, intelligence-driven, and cloud-native cyber defense strategy. Employing a follow-the-sun model, the company ensures continuous investigative progress and analyst availability worldwide. Its Incident Response (IR) team, noted for deep expertise in digital forensics, malware analysis, and threat hunting, is supported by proprietary AI tools that enhance investigation speed and accuracy. Beyond immediate incident containment, CrowdStrike emphasizes long-term resilience through proactive services such as CrowdStrike Pulse, which provides expert-led engagements tailored to organizational needs. The firm's commitment to innovation is reflected in its strategic roadmap, which focuses on advancing capabilities with generative AI and streamlined automation to stay ahead of threats and provide enhanced client value.
Aug 27, 2025 1,811 words in the original blog post.
CrowdStrike has been recognized as a leader in the 2025 IDC MarketScape for Worldwide Exposure Management due to its innovative approach to addressing modern cybersecurity threats. The company's Falcon Exposure Management platform provides real-time visibility and risk prioritization across various domains, including endpoints, cloud, identity, and unmanaged infrastructure, without requiring complex scanner infrastructure. It integrates AI-driven prioritization and automated remediation to efficiently manage vulnerabilities and reduce risks before adversaries can exploit them. The platform leverages CrowdStrike's Threat Graph, Intel Graph, and Asset Graph to offer a unified view that correlates risks and supports proactive risk reduction. This recognition underscores CrowdStrike's commitment to redefining exposure management, emphasizing its effectiveness in unifying vulnerability management, attack surface management, and cyber asset attack surface management into a cohesive solution.
Aug 25, 2025 1,824 words in the original blog post.
CrowdStrike's blog discusses the activities of MURKY PANDA, a sophisticated China-nexus adversary known for targeting government, technology, academic, legal, and professional services sectors in North America through cloud-based cyberespionage. The adversary has demonstrated expertise in exploiting internet-facing appliances and leveraging trusted-relationship compromises in the cloud, often using advanced operational security measures to avoid detection. MURKY PANDA has exploited both n-day and zero-day vulnerabilities, including CVE-2023-3519, and utilized custom malware like CloudedHope to achieve their intelligence-gathering objectives. They have also been observed compromising SaaS providers and cloud solution providers to access downstream customers' environments, highlighting their proficiency in navigating complex cloud infrastructures. CrowdStrike's analysis emphasizes the importance of rigorous monitoring and security measures to counter such threats, especially for organizations heavily reliant on cloud environments.
Aug 21, 2025 2,795 words in the original blog post.
Between June and August 2025, CrowdStrike's Falcon platform effectively thwarted a malware campaign targeting over 300 customer environments with SHAMOS, a variant of the Atomic macOS Stealer (AMOS) developed by the cybercriminal group COOKIE SPIDER. This campaign, which exploited malvertising to lure users to fake macOS help websites, involved malicious one-line installation commands that bypassed Gatekeeper security checks, installing Mach-O executables directly onto victims' devices to harvest sensitive data and cryptocurrency. The campaign's success highlights the ongoing popularity of such methods among eCrime actors, who utilize tactics like spoofing legitimate businesses in Google Advertising profiles to increase the reach of their malicious websites. CrowdStrike's assessment suggests that these techniques will continue to be favored by eCrime actors due to their effectiveness in bypassing security measures, emphasizing the need for robust endpoint protection strategies like those provided by CrowdStrike's Falcon platform.
Aug 20, 2025 2,442 words in the original blog post.
CrowdStrike's blog post elaborates on the sophisticated cyber threat posed by SCATTERED SPIDER, an eCrime adversary known for its advanced tactics, techniques, and procedures (TTPs) since 2022. This adversary specializes in social engineering to gain initial access, often impersonating employees to bypass verification processes, and persists in environments by manipulating federated identity credentials. The post highlights the capabilities of CrowdStrike's Falcon Next-Gen SIEM in detecting and responding to such threats across identity, cloud, SaaS, and network layers, offering real-time insights and tailored detections. It emphasizes the importance of understanding SCATTERED SPIDER's methods to implement a defense-in-depth strategy, supported by Falcon's comprehensive security platform that integrates third-party telemetry with native intelligence to enhance visibility and detection accuracy.
Aug 14, 2025 3,599 words in the original blog post.
CrowdStrike has introduced Falcon Next-Gen Identity Security, a comprehensive solution designed to protect all types of identities, including human, non-human, and AI agents, across on-premises, cloud, and SaaS environments. This solution addresses the challenges posed by expanding identity attack surfaces as organizations increasingly adopt SaaS applications and AI agents. Traditional IAM and PAM solutions are often inadequate, leading to security gaps and complexity when dealing with identity-driven attacks. Falcon Next-Gen Identity Security combines initial access prevention, secure privileged access, identity threat detection and response, and SaaS identity security to offer unified protection. By leveraging real-time signals, threat intelligence, and AI, it provides end-to-end visibility and dynamic access control, allowing organizations to prevent and respond to identity-based threats effectively. The platform integrates identity, endpoint, cloud, and SaaS security into a single management console, offering seamless protection against modern cyber threats.
Aug 14, 2025 1,784 words in the original blog post.
CrowdStrike has been recognized as a leader in various cybersecurity sectors, notably being named the sole leader in the 2025 GigaOm Radar Report for SaaS Security Posture Management (SSPM) due to its innovative Falcon platform. This platform integrates multiple security solutions, including endpoint protection, identity security, and cloud security, offering comprehensive protection across SaaS environments. The platform's capabilities are enhanced by the integration of Adaptive Shield and the development of GenAI tools, which aim to monitor and manage AI settings to prevent data leaks. CrowdStrike's unified approach provides real-time threat detection and response, leveraging its extensive SaaS support and automated policy management to address the expanding attack surface driven by the proliferation of SaaS applications. The company's focus on securing both human and non-human identities and its commitment to continuous innovation underscore its leadership in the cybersecurity landscape.
Aug 12, 2025 1,802 words in the original blog post.
The text provides a comprehensive overview of CrowdStrike's recent advancements and initiatives in cybersecurity, highlighting their efforts in enhancing AI security, cloud security, and identity protection. Recent developments include the introduction of Threat AI, an agentic threat intelligence system, and Falcon Cloud Security's role in preventing GenAI data leaks. The text also covers Microsoft's August 2025 Patch Tuesday, which addressed 107 vulnerabilities, including critical issues in Windows and Microsoft Office, emphasizing the need for organizations to adopt robust cybersecurity strategies and prepare for Microsoft's discontinuation of Windows 10 support in October 2025. Additionally, it mentions CrowdStrike's recognition as a leader in various cybersecurity reports and its strategic acquisitions aimed at strengthening enterprise AI use.
Aug 12, 2025 3,494 words in the original blog post.
The blog post highlights CrowdStrike's strategic approach to enhancing machine learning (ML) models for cybersecurity, focusing on the prevention of data leakage during model training. By employing strategic data splitting methods, particularly blocked cross-validation, CrowdStrike aims to improve the reliability of ML models in detecting novel threats by reducing overconfidence and overfitting associated with train-test leakage. This approach acknowledges the dependencies within cybersecurity data, ensuring more accurate threat predictions. The post underlines the importance of rigorous data partitioning and evaluation strategies to optimize the performance of machine learning models, ultimately contributing to CrowdStrike's mission of effectively preventing breaches.
Aug 11, 2025 2,708 words in the original blog post.
In September 2025, CrowdStrike has been recognized as a leader in various cybersecurity domains, including Managed Detection and Response (MDR) services in Europe as per The Forrester Wave report. The company has launched CrowdStrike Signal, an AI-powered detection engine that enhances threat detection by learning from each customer's environment, thus identifying early-stage threats often overlooked by traditional tools. CrowdStrike also reported on the September 2025 Patch Tuesday, highlighting two publicly disclosed zero-day vulnerabilities among 84 Common Vulnerabilities and Exposures (CVEs). Additionally, the company continues to innovate with its Falcon Complete Hub, which transforms MDR visibility into actionable insights, and remains at the forefront of enhancing cybersecurity measures across diverse sectors, including cloud security, threat hunting, and endpoint security.
Aug 06, 2025 1,671 words in the original blog post.
CrowdStrike is advancing its cybersecurity services with several key innovations, focusing on next-generation identity security, data protection, and vulnerability management. In its latest announcements, the company introduced new AI Security Services designed to help organizations secure their AI systems and enhance operational readiness, amidst the growing use of AI by both enterprises and adversaries. The services include AI Systems Security Assessment and AI for SecOps Readiness, offering organizations strategic guidance to manage AI risks and improve governance. Additionally, CrowdStrike has expanded its Falcon platform capabilities, emphasizing risk-based patching and unified data protection to thwart data leaks, and has been recognized as a leader in various industry assessments such as the IDC MarketScape and Forrester Wave. The company's threat intelligence and incident response expertise underpin these services, ensuring that organizations can effectively respond to the evolving threat landscape.
Aug 06, 2025 1,769 words in the original blog post.
CrowdStrike has introduced a new release of Falcon Adversary Intelligence that personalizes threat intelligence for each customer based on their unique environment, industry, and risk factors. This update aims to transform how organizations access and act on threat intelligence by integrating real-time insights directly into analyst workflows, enhancing SOC operations with faster triage, deeper investigations, and more confident responses. With tools like Intelligence Explorer and the Indicator App, analysts can now efficiently pivot from indicators of compromise to conduct thorough investigations, minimizing noise and improving response times. The release leverages CrowdStrike's comprehensive adversary intelligence to deliver relevant and actionable insights, helping organizations proactively address the most pressing threats. Existing customers will receive these updates automatically, providing them with the ability to reduce noise and enhance analyst efficiency across the CrowdStrike Falcon platform.
Aug 05, 2025 1,669 words in the original blog post.
CrowdStrike has been recognized as a leader in multiple security domains, including incident response services and exposure management, as noted in the 2025 IDC MarketScape reports. The company is advancing its security capabilities by acquiring Onum to enhance data-driven operations in Agentic Security Operations Centers (SOCs) and integrating with the OpenAI ChatGPT Enterprise Compliance API to improve visibility and governance in AI-driven environments. CrowdStrike’s Falcon Shield aims to centralize control over AI agents, facilitating compliance and security governance as enterprises increasingly adopt generative AI technologies. The integration allows security teams to inventory and monitor AI agent usage, ensuring they align with enterprise policies while maintaining innovation. The company also explores AI and machine learning to strengthen its threat detection and response strategies, with a focus on preventing cloud breaches and enhancing endpoint security through advanced threat intelligence and AI-powered tools.
Aug 05, 2025 1,715 words in the original blog post.
CrowdStrike's Falcon Shield is a cybersecurity solution designed to enhance visibility and control over AI agents within SaaS environments, addressing the risks associated with their rapid integration into business processes. As these agents become more prevalent, they often create potential vulnerabilities due to misconfigurations and excessive permissions, which adversaries can exploit. Falcon Shield maps AI agents to their creators, detects anomalies, and enforces security policies, providing a comprehensive view of SaaS security posture across various domains. It integrates with OpenAI ChatGPT Enterprise Compliance API for centralized monitoring and governance of GPT agents, ensuring alignment with enterprise policies. The platform also utilizes CrowdStrike Falcon Fusion SOAR to automate containment and resolution processes, making AI agent protection a seamless part of an organization's overall cybersecurity strategy.
Aug 05, 2025 2,048 words in the original blog post.
In August 2025, CrowdStrike, a leading cybersecurity firm, has been recognized as a leader in several categories by the 2025 IDC MarketScape, including Worldwide Incident Response Services and Exposure Management. The company plans to acquire Onum to enhance how data influences the Agentic SOC, reflecting its commitment to advancing cybersecurity operations. Additionally, CrowdStrike has developed a sophisticated AI-powered attack simulation engine to explore how adversaries use AI to execute complex, multi-stage cyberattacks, revealing the need for adaptive defense strategies like Charlotte AI, which aids in detection, triage, and response. This innovation emphasizes the critical balance between human expertise and machine intelligence in combating AI-augmented cyber threats.
Aug 04, 2025 3,850 words in the original blog post.
The CrowdStrike 2025 Threat Hunting Report highlights the evolving threat landscape where adversaries increasingly leverage artificial intelligence to enhance their operations, scale attacks, and exploit vulnerabilities within AI technologies. The report reveals a significant rise in cloud intrusions and cross-domain attacks, with notable examples such as SCATTERED SPIDER's proficiency in bypassing security defenses and employing vishing to move laterally across environments. The report also underscores the prevalence of eCrime activities, which accounted for 73% of interactive intrusions, and the adaptation of adversaries in executing malware-free attacks to evade legacy detection methods. Additionally, it emphasizes the growing threat from nation-state actors, particularly China-nexus groups, targeting telecom networks and utilizing cloud misconfigurations. CrowdStrike's report provides critical insights into these challenges, aiding organizations in understanding and countering the sophisticated tactics of modern cyber adversaries.
Aug 04, 2025 1,843 words in the original blog post.