Home / Companies / Crowdstrike / Blog / January 2026

January 2026 Summaries

12 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
AI agents are revolutionizing enterprise operations by interpreting prompts and executing tasks, but their flexibility also introduces security vulnerabilities known as agentic tool chain attacks. These attacks target the reasoning layer of AI agents, where decisions about tool usage are made, by manipulating language, metadata, and context. The Model Context Protocol (MCP) centralizes tools on servers, enhancing development but increasing risk, as a compromise of one server could affect all connected agents. The text details three types of attacks: tool poisoning, where hidden malicious instructions are embedded in tool descriptions; tool shadowing, which manipulates tool parameters across unrelated tools; and rugpull attacks, where server behavior changes post-integration. These attacks can result in data breaches and unauthorized actions without triggering traditional security alarms. Mitigation strategies include tool governance, MCP server identity controls, pre-execution guardrails, and enhanced observability. These measures aim to secure AI agents by ensuring they operate within defined boundaries, crucial as AI becomes more autonomous and integrated into enterprise systems.
Jan 30, 2026 2,238 words in the original blog post.
LABYRINTH CHOLLIMA, a North Korean cyber adversary tracked by CrowdStrike, has evolved into three distinct entities: GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and the core LABYRINTH CHOLLIMA group, each with specialized objectives and malware. GOLDEN CHOLLIMA focuses on consistent, smaller-scale cryptocurrency thefts, using cloud-focused tactics and sophisticated malware like Jeus and its variants. PRESSURE CHOLLIMA targets high-value cryptocurrency heists and is known for deploying advanced implants and malware like SparkDownloader. Meanwhile, the core LABYRINTH CHOLLIMA group continues to focus on espionage, targeting industrial, logistics, and defense sectors using advanced malware like FudModule. Despite their operational independence, these groups share tools and infrastructure, indicating centralized coordination within the DPRK cyber ecosystem, highlighting the strategic segmentation of DPRK’s cyber operations to pursue multiple objectives simultaneously amid international sanctions.
Jan 29, 2026 2,698 words in the original blog post.
Data Protection Day 2026 underscores the evolving nature of data protection in the AI era, emphasizing the need for operational resilience beyond mere regulatory compliance. As global cyber threats, identity abuse, and AI adoption accelerate, traditional compliance-centric approaches are insufficient to address the new risk landscape characterized by the exponential growth and movement of data across platforms. CrowdStrike highlights the importance of integrating security with real-time operational response, focusing on the intersection of legal safeguards, technical controls, and organizational processes. The company addresses internal risks and AI-related vulnerabilities through its Falcon AI Detection and Response, which secures AI interactions and aligns security with operational resilience. Additionally, CrowdStrike's approach combines regional data residency with global protection, advocating for data protection as a dynamic element of cyber resilience rather than a static compliance task.
Jan 28, 2026 2,227 words in the original blog post.
CrowdStrike has been recognized as a Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for Endpoint Protection Platforms report, marking its sixth consecutive recognition. The CrowdStrike Falcon® platform, noted for its AI-native security capabilities, unifies and automates defenses across endpoints, identity, cloud, and data, earning a 97% Willingness to Recommend score from users. The platform's effectiveness is supported by high ratings for product capabilities and deployment experience from diverse industries. CrowdStrike's innovations, such as remote ransomware prevention and AI-driven threat detection models, have solidified its leadership position, further validated by success in the 2025 MITRE ATT&CK Enterprise Evaluations and a Forrester Consulting study reporting a 273% ROI. This comprehensive approach to cybersecurity underscores CrowdStrike’s commitment to empowering organizations against evolving threats while maintaining strong customer trust and satisfaction.
Jan 28, 2026 2,247 words in the original blog post.
USB drives and other portable storage devices pose a significant risk to enterprise security by facilitating both data exfiltration and malicious intrusions. These devices allow employees and attackers to bypass network-based controls, leading to potential data theft and the introduction of malware, as evidenced by campaigns from adversaries like MUSTANG PANDA. CrowdStrike addresses these threats with Falcon Data Protection and Falcon Device Control, which provide real-time protection by managing data handling on endpoints and preventing unauthorized device interactions. These solutions offer a unified defense by operating through a single sensor platform, simplifying management and enhancing the security of removable media activities.
Jan 21, 2026 2,343 words in the original blog post.
CrowdStrike's "The Architecture of Agentic Defense: Inside the Falcon Platform" outlines the challenges and solutions in modern cybersecurity, emphasizing the need for an integrated system where data, semantic meaning, and AI-driven processes operate cohesively. The blog discusses the limitations of current AI tools that work on fragmented data requiring manual correlation, which hinders rapid response to AI-accelerated attacks. The Falcon Platform aims to overcome these limitations through its Enterprise Graph, which unifies data across security domains, and Charlotte AI expert agents that apply consistent reasoning frameworks. These agents perform tasks like detection triage and malware analysis, operating with consistent inputs and explainable decision paths. The platform also introduces Charlotte AgentWorks for creating custom agents to address unique organizational requirements, while Charlotte Agentic SOAR offers adaptive orchestration that constructs response logic from evidence rather than static templates. This dynamic architecture seeks to provide scalable, governed, and adaptable security operations that keep pace with evolving adversary tactics.
Jan 16, 2026 2,982 words in the original blog post.
In January 2026, Microsoft released a security update addressing 114 vulnerabilities, including three zero-day exploits, as part of its Patch Tuesday initiative. The update included fixes for various critical vulnerabilities across Microsoft Windows, Office, and security components, such as remote code execution and elevation of privilege issues. Notably, an actively exploited zero-day vulnerability in Windows Desktop Window Manager was addressed, which previously allowed attackers to access sensitive system memory. The patch also handled critical vulnerabilities in Microsoft Office, such as those allowing remote code execution through malicious emails or links, and a critical elevation of privilege vulnerability within Windows Graphics. Despite these updates, some vulnerabilities remain unpatched, necessitating alternative mitigation strategies to maintain robust cybersecurity. The CrowdStrike Falcon platform aids in managing these vulnerabilities through its comprehensive exposure management capabilities, helping organizations to identify and prioritize security threats efficiently.
Jan 13, 2026 2,577 words in the original blog post.
CrowdStrike has announced its intention to acquire Seraphic, a leader in browser runtime security, to enhance its Falcon platform and extend zero-trust protections into the browser environment. This strategic move will enable secure access to corporate resources across any browser and device, addressing the security challenges posed by distributed workforces that rely heavily on web-based applications and AI tools. The integration of Seraphic's browser-native protection will provide real-time visibility and control within browser sessions, mitigating risks such as credential abuse, session hijacking, and AI-driven threats, while maintaining user productivity without requiring infrastructure changes. Additionally, the acquisition will complement CrowdStrike's recent agreement to acquire SGNL, further strengthening its unified identity security strategy by embedding continuous authorization and context-aware security measures directly within the browser, ensuring a seamless and secure user experience across corporate and contractor devices. This move is part of CrowdStrike's broader effort to secure the modern, AI-powered workforce by transforming the Security Operations Center (SOC) with enhanced correlation of endpoint and browser signals, thereby offering a comprehensive defense against evolving cyber threats.
Jan 13, 2026 1,951 words in the original blog post.
AI tool poisoning presents a significant threat to AI agents by exploiting how they interpret tool descriptions, potentially leading to data breaches and unauthorized actions. This attack method involves embedding hidden instructions or malicious metadata within the descriptions of tools that AI agents use, which can cause agents to execute malicious actions like leaking sensitive data or running unauthorized code. Different forms of tool poisoning, such as hidden instructions, misleading examples, and permissive schemas, can manipulate AI agents' behavior, compromising their reliability and trustworthiness. To counter these threats, organizations are encouraged to implement security measures, including runtime monitoring, validation of tool descriptions, input sanitization, and strict identity and access controls. Understanding these risks and adopting effective security controls are crucial for protecting AI agents from such vulnerabilities.
Jan 09, 2026 2,264 words in the original blog post.
CrowdStrike has announced its agreement to acquire SGNL, a leader in identity-first security, to enhance its Falcon Next-Gen Identity Security platform. This acquisition aims to address the growing identity attack surface fueled by the proliferation of SaaS and AI-powered applications, as well as the increasing number of non-human identities such as service accounts and AI agents. SGNL will enable continuous, context-aware authorization by dynamically managing access privileges based on real-time risk assessments, effectively replacing static access models. By integrating SGNL, CrowdStrike plans to deliver a modern identity protection solution that secures both human and non-human identities across hybrid cloud environments, strengthening the overall security posture and preventing identity-based attacks. This move is part of CrowdStrike's broader strategy to adapt to the evolving cybersecurity landscape in the AI era and ensure comprehensive protection across diverse identity types.
Jan 08, 2026 1,988 words in the original blog post.
CrowdStrike's Malware Analysis Agent, highlighted in this blog, is a cutting-edge tool designed to detect malware efficiently at machine speed, as demonstrated in the 2025 MITRE ATT&CK Enterprise Evaluations where it achieved 100% detection and protection with no false positives. This agent automates the traditionally time-consuming and complex malware analysis process by integrating static and dynamic analysis, pattern matching, and classification into a single orchestrated workflow. It uses AI to synthesize information from multiple tools, rapidly transforming suspicious files into actionable intelligence with detailed behavioral analysis and remediation recommendations. The agent's ability to integrate with existing security solutions enhances its utility, allowing security teams to respond more promptly and effectively to threats. This innovation supports CrowdStrike’s broader vision for an agentic security operations center (SOC) capable of countering AI-powered adversaries by accelerating critical processes and maintaining high-quality analysis across increased alert volumes.
Jan 06, 2026 2,400 words in the original blog post.
CrowdStrike is collaborating with NVIDIA to optimize NVIDIA's Nemotron models for enhanced security operations, focusing on adapting large language models (LLMs) for security-specific workloads while maintaining high performance and security. This effort includes creating a natural language-to-CrowdStrike Query Language (CQL) translation model by utilizing real-world queries and synthetic data generated with NVIDIA NeMo Data Designer. The project addresses challenges like query duplication and privacy concerns by employing techniques such as deduplication using Abstract Syntax Trees (ASTs) and a custom PII scrubbing pipeline. By fine-tuning models like Llama Nemotron Super 49B, CrowdStrike achieved significant gains in query validity and semantic accuracy, enabling analysts to concentrate on threat investigation rather than query syntax, thus enhancing efficiency in security operations. The ongoing collaboration aims to further explore NVIDIA's Nemotron 3 models to optimize performance, cost, and capability balance in security operations across various use cases.
Jan 05, 2026 2,647 words in the original blog post.