February 2026 Summaries
15 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CrowdStrike has introduced FalconID, a phishing-resistant multi-factor authentication (MFA) solution integrated with its Falcon platform, aimed at enhancing identity security by continuously assessing risk signals related to identity, endpoint, and SaaS security. This development addresses the increasing sophistication of cyber adversaries who utilize AI to bypass traditional security measures and exploit legitimate identities. FalconID employs FIDO2-based biometric authentication, eliminating the need for passwords, push notifications, and one-time codes, and instead relies on trusted devices and domains for user verification. CrowdStrike's acquisition of SGNL further augments this offering by enabling continuous, context-aware authorization beyond initial login, eliminating standing privileges, and allowing dynamic access adjustments based on real-time risk assessments. Together, these advancements form part of CrowdStrike's broader strategy to deliver a unified identity security framework that adapts to shifting threats, ensuring security across all types of identities and environments.
Feb 26, 2026
1,760 words in the original blog post.
In 2025, the cyber threat landscape evolved significantly, with adversaries increasingly leveraging AI-enabled techniques to bypass traditional security measures. The CrowdStrike 2026 Global Threat Report highlights that adversaries are now focusing on exploiting trusted access paths, AI systems, and supply chain vulnerabilities to evade detection and gain unauthorized access. Notably, there was a 65% increase in the speed of eCrime breakout times and an 89% rise in attacks by AI-enabled adversaries, with 82% of these detections being malware-free. The report also observes a marked increase in zero-day exploits, cloud-conscious intrusions, and social engineering techniques such as fake CAPTCHA lures. Specific threat actors, including those with China and North Korea nexuses, have intensified their operations, indicating a need for organizations to enhance their defensive strategies against these sophisticated tactics.
Feb 24, 2026
1,786 words in the original blog post.
Typosquatting, a technique where threat actors register domains with slight misspellings or variations of legitimate company names, has evolved into a sophisticated threat in the cyber landscape, according to a CrowdStrike blog. These malicious campaigns often exploit weaknesses in domain registration processes, allowing adversaries to create credible-looking infrastructure with minimal verification. Techniques such as strategic HTTP redirects, geo-targeted content delivery, and domain sale page camouflage are employed to evade detection and maximize impact, enabling the delivery of phishing emails and credential harvesting while maintaining an appearance of legitimacy. The blog emphasizes the need for organizations to adopt a multi-layered defense strategy, leveraging tools like CrowdStrike Falcon® Adversary Intelligence to monitor domain registrations and disrupt these threats early.
Feb 23, 2026
2,278 words in the original blog post.
CrowdStrike has introduced "AI Unlocked: Decoding Prompt Injection," an interactive online challenge designed to enhance security teams' understanding of prompt injection attacks within the AI landscape. This hands-on simulation allows participants to experience the attacker's perspective by navigating through three virtual rooms, each escalating in difficulty, to uncover secret phrases using prompt injection techniques. Prompt injection attacks embed adversarial instructions into data consumed by large language models or AI agents, potentially leading to data exfiltration or unintended actions. As AI systems proliferate, the significance of educating security, developer, and AI teams on these vulnerabilities has become crucial, particularly highlighted by concerns over open-source AI agents like OpenClaw. CrowdStrike's initiative aims to transform theoretical AI security concepts into practical knowledge, equipping participants to implement robust defenses against this emerging threat.
Feb 18, 2026
1,544 words in the original blog post.
CrowdStrike has introduced advanced tools to enhance insider threat detection, leveraging its Falcon Data Protection and Next-Gen Identity Security platforms. These tools enable organizations to identify and respond to insider threats through comprehensive dashboards that utilize behavioral analytics, multi-source correlation, and policy enforcement. The dashboards, including the Insider Threat Analytics and User Activity Investigation, offer features such as multi-layer detection architecture, advanced behavioral analytics, risk-based prioritization, and policy compliance frameworks to detect and investigate malicious actions or negligent behavior by insiders. By establishing user behavior baselines and detecting deviations, these tools help organizations mitigate risks by identifying potential threats at early stages and prioritizing responses based on threat severity. The integration of platforms like Workday enhances risk scoring with HR context, while detailed analysis features allow security teams to proactively manage insider threats and protect sensitive data before significant harm occurs.
Feb 18, 2026
5,139 words in the original blog post.
CrowdStrike has been recognized as a Customers’ Choice in the 2026 Gartner Peer Insights™ “Voice of the Customer for User Authentication” report, marking the second consecutive year the company has achieved this honor, with the highest volume of verified reviews and more five-star ratings than any other vendor. The report highlights a 96% willingness to recommend rating, reflecting CrowdStrike’s commitment to providing top-tier, AI-powered identity security. The CrowdStrike Falcon® platform offers continuous, real-time identity protection, crucial as AI agents and non-human identities become more prevalent in enterprise environments. This recognition underscores CrowdStrike's mission to deliver a unified identity fabric that secures all types of identities across the modern attack chain. Additionally, CrowdStrike plans to acquire SGNL to further strengthen its authentication leadership by integrating continuous, dynamic authorization into the Falcon platform, thereby enhancing its ability to protect identities across their entire lifecycle.
Feb 12, 2026
1,901 words in the original blog post.
CrowdStrike's Falcon Fusion SOAR aims to simplify and scale security operations center (SOC) automation, allowing teams to start with manageable workflows and build towards more complex, AI-powered processes. The platform provides a unified system for orchestrating agents and automating actions across security processes, with recent enhancements focusing on safe testing, accelerated workflow creation through a Workflow Generation Agent, and generative AI for data transformation. By starting with frequent, well-defined workflows such as malware triage or phishing response, SOC teams can see immediate benefits, build confidence in automation, and establish scalable patterns. The Data Transformation Agent, powered by AI, simplifies complex data manipulations, making it accessible to more analysts and ensuring workflows proceed smoothly. CrowdStrike's approach empowers analysts to maintain control while leveraging automation for efficiency, with resources like "The Essential SOAR Playbook" offering practical guidance for implementing Falcon Fusion SOAR effectively.
Feb 11, 2026
2,164 words in the original blog post.
CrowdStrike's February 2026 Patch Tuesday overview highlights the mitigation of 59 vulnerabilities, including six zero-days, by Microsoft, with key vulnerabilities affecting Windows Remote Desktop, MSHTML Framework, and Microsoft Word. These vulnerabilities, actively exploited in the wild, pose significant security risks through techniques such as privilege elevation and security feature bypasses, often requiring user interaction and exploiting social engineering. Additionally, the report details critical vulnerabilities in Microsoft Azure and ACI Confidential Containers, emphasizing the role of proactive security measures and transparency in cloud service vulnerability management. CrowdStrike provides tools like the Falcon platform to help organizations manage and prioritize these vulnerabilities, leveraging the Common Vulnerability Scoring System (CVSS) to communicate severity and guide mitigation strategies.
Feb 10, 2026
3,090 words in the original blog post.
CrowdStrike's innovative approach to cybersecurity is powered by a human-AI feedback loop that synergizes the speed and data processing capabilities of artificial intelligence with the nuanced judgment of human experts. This system enables the detection and prevention of sophisticated cyber threats by continuously integrating real-time insights from CrowdStrike's elite analysts into their AI models. The process involves annotating and interpreting vast amounts of security telemetry, allowing AI agents to learn from expert reasoning and adapt to new adversarial tactics. This collaboration enhances the accuracy and efficiency of security operations, enabling quick and informed responses to threats. CrowdStrike's Falcon platform exemplifies this integration, providing a robust AI-native defense system that is continuously refined through feedback from ongoing security operations, ensuring that both AI and human agents are always aligned against evolving cyber challenges.
Feb 10, 2026
2,236 words in the original blog post.
CrowdStrike has been recognized as the sole vendor to receive the Customers’ Choice distinction in the 2025 Gartner® Peer Insights™ Voice of the Customer for External Attack Surface Management (EASM) for two consecutive years. The recognition is based on peer reviews, highlighting CrowdStrike Falcon® Exposure Management's ability to provide continuous and accurate visibility into both known and unknown internet-facing assets, which helps organizations prioritize and reduce the risk of vulnerabilities. The platform integrates external exposure insights with internal context, offering a unified approach to exposure management without the operational burden of additional tools. Customers have praised its effectiveness in identifying assets and monitoring exposures, earning it an overall rating of 4.7 out of 5 stars with a 93% willingness to recommend, based on 29 reviews.
Feb 09, 2026
1,881 words in the original blog post.
Web shells are a significant threat to Linux servers and containers, often evading detection for long periods and enabling adversaries to maintain persistent access, execute processes, access filesystems, and tunnel network connections. These malicious scripts, frequently used in targeting critical web applications, pose high risks of data exfiltration, lateral movement, and ransomware attacks. CrowdStrike has enhanced its Falcon sensor for Linux to better detect PHP web shells, particularly those that are obfuscated or pre-existing, with features like "On write script file visibility" and "Enhance PHP visibility." These improvements have led to the detection of numerous web shells by providing real-time awareness of script activities, allowing security teams to gain a comprehensive view of adversary actions during incidents. The Falcon platform's ability to monitor script execution and dynamically evaluate PHP code increases detection efficacy and aids in analyzing sophisticated intrusions, such as those involving Zimbra mail servers. These advancements underscore the importance of enabling these detection features to safeguard against web shell threats effectively.
Feb 05, 2026
2,404 words in the original blog post.
OpenClaw, an open-source AI agent known for its expansive capabilities and integration with LLMs and external APIs, presents significant security concerns due to its potential to be commandeered as a backdoor agent if misconfigured. The rapid rise in its popularity, underscored by its 150,000 GitHub stars, increases the risk of adversaries exploiting OpenClaw for malicious activities, such as leaking sensitive information or executing unauthorized tasks. The CrowdStrike Falcon platform offers solutions to identify, monitor, and mitigate risks associated with OpenClaw by providing visibility into deployments and detecting potential threats. Falcon's extensive capabilities, like endpoint security modules and AI Service Usage Monitor dashboards, enable organizations to manage OpenClaw's exposure and ensure secure operations. Additionally, Falcon for IT provides detection and removal workflows to eradicate OpenClaw from affected systems. The platform also focuses on mitigating prompt injection attacks, which pose a severe threat by allowing adversaries to hijack AI agents' capabilities and execute malicious actions. CrowdStrike's AI Detection and Response (AIDR) guardrails effectively prevent such attacks, ensuring AI agents like OpenClaw are protected against exploitation while maintaining their productivity benefits.
Feb 04, 2026
3,054 words in the original blog post.
CrowdStrike's Falcon platform achieved a perfect 100% score in SE Labs' extensive ransomware test, demonstrating its robust capabilities in detecting, protecting against, and accurately identifying ransomware threats without false positives. The test involved 649 ransomware files and simulated attacks from 11 adversary groups, measuring the platform's ability to provide full attack visibility and effective threat neutralization. This outstanding performance underscores CrowdStrike's ongoing commitment to cybersecurity innovation, leveraging advanced technologies like AI-powered indicators of attack and machine learning to stay ahead of sophisticated threats. The Falcon platform's success in this rigorous evaluation, along with its history of awards and third-party recognitions, highlights its role as a leader in endpoint protection and its effectiveness in maintaining security in an increasingly complex digital landscape.
Feb 03, 2026
2,379 words in the original blog post.
CrowdStrike has been recognized as a Customers' Choice in the 2026 Gartner Peer Insights™ Voice of the Customer report for Application Security Posture Management (ASPM) Tools, highlighting its top customer ratings for product capabilities and deployment experience. This recognition underscores the effectiveness of CrowdStrike's Falcon ASPM in providing real-time insights into application interactions, helping organizations to navigate the complexities of modern, dynamic application ecosystems. Falcon ASPM is part of CrowdStrike's unified cloud-native application protection platform, which offers comprehensive asset visibility and risk-based prioritization to cut through security noise and identify critical vulnerabilities. Customers have praised its smooth integration with existing DevSecOps tools and its unique capability to map dependencies in a graph view, facilitating a clearer understanding of security risks. As application environments evolve, CrowdStrike's Falcon ASPM aims to secure applications throughout their lifecycle, from code to cloud to runtime, by unifying application, cloud, and runtime signals, thereby reducing complexity while enhancing security posture.
Feb 03, 2026
1,751 words in the original blog post.
CrowdStrike is at the forefront of securing AI systems by providing comprehensive protection through its Falcon platform, which integrates security controls across cloud infrastructure, data pipelines, identities, and endpoints. As organizations like WEX, Med Center Health, and Genesys incorporate AI into their workflows, they face new security challenges that require maintaining visibility, identity control, data protection, and continuous monitoring at machine speed. CrowdStrike Falcon ensures secure AI adoption by unifying security across various domains, allowing these organizations to innovate confidently while managing risks. WEX uses Falcon Cloud Security for seamless AI infrastructure protection, Med Center Health employs Falcon Data Protection to safeguard patient data, and Genesys embeds security into its development lifecycle to maintain high data protection standards. By using an integrated approach, the Falcon platform helps these organizations secure AI workloads and maintain compliance, trust, and operational efficiency as they scale their AI capabilities.
Feb 02, 2026
2,047 words in the original blog post.