March 2026 Summaries
19 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
CVE-2026-20929 is a significant cybersecurity vulnerability that exploits Kerberos authentication via DNS CNAME record abuse, allowing attackers to relay authentication to Active Directory Certificate Services (AD CS) and obtain persistent access through certificate enrollment. This attack vector is particularly dangerous as it bypasses traditional password-based security measures and can persist for extended periods. CrowdStrike addresses this threat by leveraging its Falcon platform, which offers real-time protocol inspection and behavioral correlation to detect anomalous authentication patterns, providing comprehensive protection against such sophisticated threats. The platform's multi-layered approach combines automated detection and proactive threat hunting, enabling organizations to maintain security integrity within their Active Directory environments.
Mar 31, 2026
2,464 words in the original blog post.
CrowdStrike is spearheading a shift towards agentic security operations with the introduction of Charlotte AI AgentWorks and Charlotte Agentic SOAR, designed to transform traditional security operations centers (SOCs) into AI-driven ecosystems. This approach emphasizes the orchestration of intelligent, context-aware agents that enhance human expertise by automating routine tasks and enabling strategic oversight. By integrating with leading AI models and infrastructure services, Charlotte AI AgentWorks serves as a hub for building and scaling security agents, while Charlotte Agentic SOAR orchestrates these agents across complex workflows. This model promotes collaboration and innovation, allowing partners and service providers to develop specialized security solutions on the Falcon platform. To encourage AI adoption, CrowdStrike offers free AI credits, enabling organizations to experiment with and integrate agentic operations. The goal is to redefine the security landscape by fostering a collaborative ecosystem that unites intelligence, orchestration, and action at scale, setting the stage for a future where security operations are more efficient and resilient.
Mar 25, 2026
1,879 words in the original blog post.
CrowdStrike has introduced its agentic Managed Detection and Response (MDR) and SOC Transformation Services to help organizations modernize their security operations in an era where adversaries exploit AI to evade detection. The agentic MDR, delivered through CrowdStrike Falcon Complete, combines deterministic automation with expert oversight to stop breaches at machine speed while maintaining accountability. It leverages adaptive AI agents that learn from live adversary behavior to enhance the speed and accuracy of threat response. Meanwhile, the SOC Transformation Services aim to equip organizations with the necessary foundations for agentic SOC operations by modernizing core elements such as SIEM, data pipelines, and workflows. These services are designed to help enterprises transition from tool adoption to achieving repeatable outcomes, enabling them to effectively respond to modern threats with advanced detection and automation capabilities.
Mar 24, 2026
1,911 words in the original blog post.
CrowdStrike has introduced Falcon Data Security, a solution designed to protect sensitive data across modern, dynamic business environments where data is constantly being created, accessed, and moved. This new approach emphasizes real-time visibility and control over data movement, allowing organizations to detect and prevent data theft by transforming data movement into a security signal. Falcon Data Security integrates advanced classification and real-time monitoring to safeguard data across endpoints, SaaS applications, cloud services, and more, utilizing the unified Falcon sensor to provide comprehensive protection. By leveraging eBPF-based telemetry and the broader context of the Falcon platform, security teams can quickly assess and respond to potential threats, distinguishing between routine activities and genuine risks. This model shifts data security from a passive visibility tool to an active breach prevention mechanism, aiming to secure sensitive information as it flows through various digital channels.
Mar 24, 2026
1,894 words in the original blog post.
CrowdStrike has unveiled new enhancements to its Falcon Cloud Security platform, introducing three industry-first capabilities aimed at addressing existing gaps in cloud-native application protection platforms (CNAPPs). These innovations include Application Explorer, which provides application-layer visibility to correlate cloud infrastructure risks with business applications, Adversary Intelligence for Cloud Risks, which maps cloud risks to known adversary behavior for prioritized risk management, and Timeline Explorer, offering automated root cause analysis to streamline risk investigation and remediation. These features are designed to help organizations better understand and mitigate cloud risks by focusing on real-world adversary behavior and providing comprehensive insights into how applications interact with infrastructure, ultimately enabling faster and more effective security responses to prevent data breaches.
Mar 24, 2026
2,525 words in the original blog post.
CrowdStrike has introduced "Flex for Services," an extension of the Falcon Flex model, to provide organizations with flexible access to its elite cybersecurity services, adapting to the rapidly changing threat landscape. This model allows customers to tailor their service consumption, aligning it with their evolving security needs without the constraints of traditional procurement cycles. Flex for Services offers pre-arranged incident response coverage, reducing delays associated with contracting and onboarding new providers during crises. It operates independently from standard platform subscriptions, catering to those requiring committed response times or engaging in large projects. Additionally, the Zero Dollar Flex Fund offers 200 hours of free services for eligible first-time customers, facilitating easier access to CrowdStrike's expertise and ensuring readiness and operational preparedness. This approach aims to modernize how organizations engage cybersecurity services, moving at the speed of emerging threats and making expert support more accessible.
Mar 24, 2026
1,720 words in the original blog post.
CrowdStrike's Falcon Next-Gen SIEM is being enhanced to support third-party endpoint detection and response (EDR) solutions, starting with Microsoft Defender, allowing organizations to modernize their Security Operations Center (SOC) without replacing existing endpoint agents. This integration aims to address the challenges posed by increasing architectural complexity and data visibility tradeoffs in traditional systems, which often result in slower detection and delayed responses. Falcon Next-Gen SIEM offers a data-agnostic path to SOC transformation by eliminating the "data tax" and providing index-free, petabyte-scale search performance, AI-native threat detection, and agentic automation across diverse environments. Innovations such as Falcon Onum are introduced to optimize data control, reduce noise, and lower storage costs, while federated search capabilities allow efficient data management across live, network, and archived sources. The platform also supports third-party indicator management to operationalize threat intelligence at scale and features a Query Translation Agent to simplify migration from legacy systems. By unifying endpoint, log, network, and intelligence data within a single high-speed platform, CrowdStrike is redefining SIEM by eliminating traditional tradeoffs between cost, visibility, and flexibility, thereby enabling organizations to modernize their SOC on their own terms.
Mar 23, 2026
2,193 words in the original blog post.
CrowdStrike has announced a series of innovations within its Falcon platform aimed at enhancing AI security and governance across multiple environments, including endpoints, SaaS, and cloud. These developments address the emerging vulnerabilities associated with AI adoption, such as indirect prompt injection and agentic tool chain attacks, by expanding AI detection and response capabilities to cover desktop applications and containerized workloads. The platform now offers improved visibility and governance of AI agents across SaaS platforms, enabling organizations to monitor agent behavior and manage risks associated with shadow AI. Additionally, new tools provide real-time data flow visibility to ensure compliance and prevent data leaks within AI pipelines. These advancements reflect CrowdStrike's commitment to securing AI's expanding attack surfaces while enabling organizations to adopt AI technologies confidently and securely without hindering innovation.
Mar 23, 2026
3,139 words in the original blog post.
CrowdStrike's analysis uncovered a complex supply chain compromise involving the trivy-action GitHub Action, commonly used in CI/CD pipelines. The compromise involved 76 out of 77 release tags of the vulnerability scanner being retroactively poisoned through a technique known as git tag repointing. This allowed a multi-stage credential stealer to execute silently before the legitimate scanner, enabling the theft of sensitive credentials and information from affected workflows. The attack exploited GitHub Actions' trust model, where actions are referenced by tags that can be silently altered, thereby highlighting the vulnerabilities in mutable references within software supply chains. Aqua Security confirmed the compromise and removed the malicious artifacts, while CrowdStrike's detection mechanisms identified the unusual script behavior, providing protection and investigation capabilities for affected organizations. The analysis underscores the importance of pinning actions by commit SHA, monitoring CI/CD environments with diligence, and treating pipeline code with the same scrutiny as production code to mitigate similar threats in the future.
Mar 20, 2026
3,485 words in the original blog post.
Europol, alongside law enforcement from six countries and industry partners, executed a technical takedown of the Tycoon2FA Phishing-as-a-Service (PhaaS) platform, which has been responsible for major phishing campaigns bypassing multifactor authentication to compromise email accounts. Despite the seizure of 330 domains forming the platform's infrastructure, the operators of Tycoon2FA have shown resilience, quickly returning to pre-disruption activity levels, and continuing to employ their tactics, techniques, and procedures (TTPs). This persistence underscores the adaptive nature of modern cyber adversaries who evolve to maintain pressure on defenders. CrowdStrike, a cybersecurity firm, has been actively involved in these disruption efforts and continues to monitor and counter the threat with its AI-based Falcon platform, emphasizing the importance of continuous vigilance and real-time threat intelligence to preemptively thwart such cyber threats.
Mar 20, 2026
3,012 words in the original blog post.
CrowdStrike has introduced a new security measure for AI applications, integrating its Falcon AI Detection and Response (AIDR) with NVIDIA NeMo Guardrails to enhance protection against runtime attacks and compliance violations as AI agents transition from experimental to mainstream business tools. This collaboration offers programmable guardrails to limit the scope of AI agent actions, preventing unauthorized transactions and data exposure. Falcon AIDR, combined with NVIDIA's models, manages data access, redacts sensitive information, and blocks prompt injections to ensure compliance and safety. The system supports over 75 classification rules, allowing businesses to enforce security while maintaining functionality across industries like finance, healthcare, customer service, and software development, by progressively applying stricter controls as applications move from development to production.
Mar 19, 2026
2,284 words in the original blog post.
At the Fal.Con Gov 2026 event, CrowdStrike unveiled a series of innovations aimed at modernizing cybersecurity for government agencies, emphasizing the need for speed and resilience in defense against increasingly sophisticated AI-driven adversaries. The new features include Falcon Flex, which offers a flexible, commitment-based model to streamline procurement and enhance platform adoption; Charlotte AI capabilities, which improve investigation efficiency via natural language interactivity and automated response agents; and Falcon for XIoT, designed to secure the expanding attack surfaces of critical infrastructure. Additionally, CrowdStrike's external attack surface management and behavioral malware analysis tools provide comprehensive visibility and threat evaluation capabilities, helping agencies proactively manage risk. These advancements are part of CrowdStrike's strategy to transition security operations from manual compliance to mission-ready, AI-enhanced defenses within a FedRAMP High authorized environment, ensuring protection for national security and mission-critical operations.
Mar 18, 2026
2,144 words in the original blog post.
CrowdStrike has expanded its Falcon Platform for Government by introducing Falcon for XIoT, a FedRAMP High authorized solution designed to enhance the security of connected assets and critical infrastructure within federal agencies. This addition provides native visibility and protection for both IT and operational technology (OT) environments, addressing the growing attack surface created by IoT devices in critical sectors such as public health and power grid controls. Falcon for XIoT employs AI-powered risk prioritization to help agencies identify and mitigate vulnerabilities in legacy systems and unsupported devices, enhancing security without disrupting operations. The platform also extends its AI-native endpoint detection and response capabilities to XIoT assets, ensuring continuous threat detection and response across unmanaged devices. By unifying IT and OT security measures, CrowdStrike aims to reduce fragmentation and blind spots in federal cybersecurity efforts, providing comprehensive protection against sophisticated threats and establishing a foundation for securing future connected government systems.
Mar 18, 2026
1,724 words in the original blog post.
CrowdStrike's Charlotte AI is revolutionizing security operations by acting as an embedded security analyst within the CrowdStrike Falcon platform, helping organizations across various industries enhance their security operations without expanding their workforce. Unlike traditional tools, Charlotte AI automates the triage, investigation, and response processes by reasoning through detections like a seasoned analyst, thereby reducing the time security teams spend on these tasks. For example, Blackbaud has reported a threefold improvement in mean time to resolve issues, while Universidad Europea de Madrid has cut investigation times by 70%. Charlotte AI's integration allows companies like Straumann Group to maintain efficiency and compliance without increasing headcount, and Addition Financial has leveraged it to streamline audit processes. By enabling faster decision-making and reducing repetitive tasks, Charlotte AI supports an "agentic SOC" model, allowing human analysts to focus on strategic and impactful security decisions.
Mar 12, 2026
2,021 words in the original blog post.
CrowdStrike has introduced Enhanced Network Visibility for macOS, offering advanced capabilities in sensor version 7.29 and later, designed to provide deeper insights and improved visibility into network traffic on macOS endpoints. This feature enhances process behavior modeling by integrating network traffic attributes, identifying application protocols, analyzing TLS traffic characteristics, and inspecting HTTP traffic. Utilizing Apple-native content filter APIs, it minimizes system impact while maximizing detection capabilities, allowing a targeted, efficient approach to network monitoring. The feature, which is opt-in, includes JA4 fingerprinting for distinguishing TLS connections and supports various protocols such as HTTP, TLS, SOCKS, and more, enabling threat hunters to leverage enhanced network capabilities for detecting and responding to threat actor activities.
Mar 11, 2026
3,420 words in the original blog post.
Microsoft's March 2026 Patch Tuesday addressed 82 security vulnerabilities, including eight classified as Critical and two that were publicly disclosed. Notable among these is a critical remote code execution vulnerability, CVE-2026-21536, in the Microsoft Devices Pricing Program, which allows unauthenticated remote attackers to execute arbitrary code through an unrestricted file upload weakness. Microsoft has remediated this vulnerability within its cloud infrastructure, requiring no action from users. Other critical vulnerabilities include issues in Microsoft Office and Excel, with the potential for remote code execution and information disclosure. Additionally, the update highlights vulnerabilities in Microsoft ACI Confidential Containers, with potential for privilege elevation and information disclosure, all of which Microsoft has addressed without requiring user intervention. The update underscores the importance of regular patching and mitigation strategies, especially for vulnerabilities that cannot be easily patched.
Mar 10, 2026
2,504 words in the original blog post.
CrowdStrike's Falcon platform is extending its cybersecurity protections to healthcare environments by incorporating Internet of Medical Things (IoMT) devices, thereby enhancing asset visibility and threat detection. With the rise in connected medical devices like infusion pumps and patient monitors, healthcare systems face increased vulnerability to cyberattacks. Falcon for XIoT will now support medical device protocols, offering continuous monitoring and anomaly detection to protect patient care. The platform aims to streamline security operations by integrating IoMT threat data into existing IT workflows, improving efficiency and response times. This initiative comes in response to the growing number of breaches in healthcare and the sector's need for robust endpoint detection and response (EDR) capabilities. CrowdStrike's cloud-native architecture allows for real-time detection, which is crucial in healthcare settings where quick response is vital.
Mar 09, 2026
1,838 words in the original blog post.
CrowdStrike's Falcon Next-Gen SIEM is designed to simplify data onboarding by utilizing sensor-native log collection, which eliminates the need for separate deployment infrastructures and traditional distribution tools, thereby reducing operational friction and improving visibility. The Falcon sensor-based deployment model automates log collector installation and management, allowing for centralized governance and faster integration of external log sources. This approach enhances the scalability and operational efficiency of security operations by extending the Falcon platform's policy-driven control to log collection, enabling security teams to manage data ingestion with the same rigor as endpoint security. The deployment model leverages policy-driven workflows and existing sensor footprints, ensuring seamless integration into existing environments and allowing faster deployment compared to traditional SIEM methods. This architecture supports the unification of endpoint and third-party telemetry within a single analytics framework, providing a high-fidelity data foundation crucial for modern security operations centers (SOCs).
Mar 06, 2026
2,102 words in the original blog post.
CrowdStrike has achieved National Cyber Security Centre (NCSC) Cyber Incident Response (CIR) Assurance, a UK government-backed standard, which verifies the company's capability, governance, and technical competence in managing serious cyber incidents. This certification emphasizes the company's commitment to high standards of incident handling and operational rigor, providing assurance to customers across the UK and Europe amid rising cyber threats, particularly in Europe where incidents are prevalent. CrowdStrike has been recognized as a leader in incident response services by both Forrester and IDC, thanks to its experienced incident responders, robust threat intelligence, and comprehensive visibility across various platforms. The company's services extend beyond immediate crisis management to include long-term resilience building through tailored services retainers, ensuring readiness and risk reduction over time. The NCSC CIR certification serves as a government-backed signal of trust, reinforcing CrowdStrike’s dedication to protecting customers during critical incidents and enhancing their cybersecurity resilience globally.
Mar 02, 2026
1,670 words in the original blog post.