June 2026 Summaries
21 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
In the context of modern work environments, browsers serve as crucial platforms where employees interact with various enterprise applications and sensitive data, making them prime targets for cyberattacks. The rise of zero-day vulnerabilities, which are exploited before patches are publicly available, highlights the risks associated with browser security. Attackers often capitalize on vulnerabilities in shared browser components like Chromium, which can affect multiple browsers simultaneously. Furthermore, even beyond zero-days, browsers are susceptible to a range of threats including phishing, credential theft, and malicious downloads. To mitigate these risks, organizations must adopt robust browser security strategies that operate within the browser session itself, like CrowdStrike Falcon Secure Access, which provides defenses against both zero-day exploits and broader attack scenarios by implementing security controls within the JavaScript execution environment. This approach is crucial for protecting users and data across diverse devices and browsers, without depending solely on timely patch deployment.
Jun 30, 2026
2,203 words in the original blog post.
CrowdStrike's June 2026 Falcon Cloud Security release introduces significant updates for Azure and Google Cloud, enhancing real-time cloud security posture management (CSPM), data security posture management (DSPM), and cloud infrastructure entitlement management (CIEM). These updates aim to provide security teams with near real-time visibility into cloud environments, enabling faster detection and remediation of misconfigurations and cloud risks across AWS, Azure, and Google Cloud. The enhancements also include expanded Cloud Risks coverage that correlates multiple cloud exposures into potential breach paths and adversary-informed risk prioritization to align with real-world attacker behavior. Additionally, the release extends DSPM capabilities to Google Cloud Storage and CIEM capabilities to Azure, while also introducing container image assessments for Windows workloads, offering a more unified security approach across multi-cloud environments.
Jun 29, 2026
2,013 words in the original blog post.
As organizations increasingly deploy AI agents to handle tasks such as HR cases, code execution, and customer interactions, they face significant identity challenges due to the dynamic and autonomous nature of these agents. Unlike human employees who authenticate once and operate within defined roles, AI agents can act on behalf of multiple users simultaneously, initiate and terminate independently, and engage other agents without human oversight. This complexity raises issues in accurately identifying the agent and user principal, complicating the enforcement of access controls, audit trail creation, and detection of scope breaches. Current OAuth access tokens lack the standardization to express the intricate relationships between agents and users, leading to potential security risks like the "confused deputy problem," where systems might grant too much access based on misinterpretations. The industry recognizes the need for standardizing how agent instance identity, user identity, and their relationships are captured, as evidenced by discussions at the IIW April 2026 "un-conference," to prevent divergent implementations and ensure robust security in AI-driven workflows.
Jun 24, 2026
2,427 words in the original blog post.
A recent CrowdStrike survey highlights significant challenges organizations face in detecting and responding to cloud threats, with 94% reporting breaches leading to data exposure or exfiltration. The primary issues include incomplete visibility across cloud environments, difficulty distinguishing legitimate from malicious activity, and fragmented security tools that hinder efficiency and scale. As AI adoption accelerates cloud growth, these visibility gaps become more pronounced, with 83% of organizations running AI/ML workloads in the cloud. Many organizations struggle to detect intrusions promptly, with 68% taking over 15 minutes to respond, and 79% of alerts being false positives or low priority. The survey reveals that cloud breaches stem from interconnected gaps in detection and response processes, exacerbated by tool fragmentation and manual investigations, which slow efforts to contain threats and create opportunities for adversaries to succeed.
Jun 22, 2026
2,065 words in the original blog post.
The blog post explores the security vulnerabilities associated with the ClickOnce technology, highlighting how threat actors can exploit its features to deliver malicious software with minimal user interaction. ClickOnce, a Microsoft technology designed for easy application deployment, can be weaponized due to its user-friendly nature, lack of awareness among users, and its ability to bypass common security mechanisms by using .application files. Threat actors exploit these features by deploying payloads through ClickOnce apps without requiring elevated privileges, leveraging the built-in updating mechanism for persistence and stealthily executing malicious code under legitimate Microsoft processes. The post also uncovers a new abuse involving COM hijacking, where attackers can impersonate a ClickOnce COM server to execute arbitrary binaries, thereby introducing a new attack vector. This method is particularly discreet as it does not disrupt existing settings, making it a potent threat that security teams must monitor. The blog concludes by emphasizing the importance of understanding ClickOnce's potential abuses and implementing robust detection strategies, such as those offered by the CrowdStrike Falcon sensor, to mitigate the risks associated with this technology.
Jun 18, 2026
4,067 words in the original blog post.
ClickOnce technology, a deployment mechanism by Microsoft, simplifies the distribution and installation of applications by allowing users to install and automatically update software with minimal interaction and without requiring administrative privileges. However, its ease of use also makes it susceptible to exploitation by threat actors for spreading malware. This two-part series explores the inner workings of ClickOnce, detailing its deployment process and potential security implications. Part 1 examines the technical aspects of how ClickOnce applications are packaged and published, highlighting several deployment scenarios involving browsers and local files. It also delves into the internals of the deployment process, including the roles of various Windows components such as dfshim.dll and dfsvc.exe. The series aims to provide a comprehensive understanding of ClickOnce and its potential vulnerabilities, with Part 2 focusing on known and newly discovered methods of abuse, as well as strategies for detection and prevention, demonstrated through the capabilities of the CrowdStrike Falcon® platform.
Jun 18, 2026
4,812 words in the original blog post.
Following the signing of Executive Order 14409 by President Trump on June 2, 2026, which emphasizes the importance of security in harnessing the benefits of advanced AI, the U.S. Executive Branch has been mobilized to collaborate with industry and AI and security research communities. This initiative aims to address the challenges posed by sophisticated AI models, particularly in light of a reported 89% increase in AI-enabled attacks in 2025. The Executive Order mandates a federal working group to prioritize the cybersecurity of civilian federal government systems and suggests deploying AI detection and response tools, improving identity protections, and leveraging agentic security operations centers to enhance defense capabilities. It also proposes a Sensitive Remediations Program to aid critical infrastructure sectors lacking resources, and encourages strategic vulnerability scanning in open-source code repositories. The EO sets a 30 to 60-day timeline for significant actions, reflecting an urgency to adapt to the rapidly evolving cyber threat landscape, with the Office of the National Cyber Director playing a pivotal role in these efforts.
Jun 17, 2026
1,934 words in the original blog post.
CrowdStrike has introduced Falcon Exposure Management for third-party environments to address the challenges posed by the rapid increase in vulnerabilities driven by frontier AI. This technology provides exploitability-driven prioritization and continuous visibility, allowing organizations to manage vulnerabilities without altering their existing endpoint infrastructures. Central to its functionality is the Exposure Prioritization Agent, which evaluates vulnerabilities based on exploitability, business impact, and adversary interest, producing a contextual risk score to focus on high-risk exposures. This approach is complemented by the Exposure Summary Agent, which offers AI-enhanced summaries for efficient decision-making. Falcon Exposure Management integrates with CrowdStrike Falcon Fusion SOAR for seamless transition from vulnerability detection to remediation, positioning organizations to effectively manage the evolving cybersecurity landscape prompted by AI advancements.
Jun 16, 2026
1,701 words in the original blog post.
CrowdStrike is redefining identity security with its new Continuous Identity model, which aims to address the complexities of modern identity landscapes comprising both human and AI agents. This approach continuously evaluates identity, device, threat, and business context to determine appropriate access levels, thereby eliminating standing privileges and responding in real time to changes in risk conditions. The initiative extends across AWS cloud infrastructure and non-human identities (NHIs), ensuring accountability and governance through automated ownership mapping. By leveraging standards like SPIFFE and the Shared Signals Framework, CrowdStrike's Falcon Next-Gen Identity Security platform provides a unified system for managing both human and machine identities, enhancing security through dynamic real-time authorization processes.
Jun 15, 2026
2,190 words in the original blog post.
AI projects in enterprises often face delays due to governance frameworks not being designed for the unique challenges posed by AI technologies, such as data leakage, model manipulation, and regulatory ambiguity. As AI systems are probabilistic and adaptive, traditional security controls and review processes prove inadequate, leading to elongated assessments and inconsistent decisions. To overcome these challenges, forward-looking CIOs are embedding security and compliance into AI strategy and design, establishing cross-functional AI governance councils, and creating "paved roads"—secure, standardized pathways for AI development. This approach allows organizations to reduce friction, accelerate AI adoption in a controlled manner, and ensure that AI is deployed responsibly, transforming it from a source of friction into a competitive advantage.
Jun 12, 2026
1,889 words in the original blog post.
CrowdStrike has been recognized as a leader in the 2026 Frost Radar™ for Cloud and Application Runtime Security (CARS) due to its innovative approach to cloud detection and response (CDR), which integrates threat intelligence into real-time detection workflows across multi-cloud and hybrid environments. The company has developed a streaming CDR architecture that processes cloud telemetry instantly, allowing for quicker detection and response compared to conventional snapshot-based systems. This advancement is part of CrowdStrike's broader strategy to connect cloud security activities with Security Operations Center (SOC) processes, thereby enhancing efficiency and reducing the latency of threat responses. CrowdStrike's growth is fueled by its single-sensor architecture, which extends protection from endpoints to cloud workloads without additional infrastructure, and its AI-powered tools that streamline security operations. The company's continued innovation focuses on strengthening runtime security, expanding Kubernetes detections, and integrating artificial intelligence workload security, aiming to further consolidate its market position and support cloud security strategies as adversaries become more sophisticated.
Jun 11, 2026
1,810 words in the original blog post.
CrowdStrike is actively advancing identity-first security by becoming a Sustaining Corporate Member of the OpenID Foundation and joining IDPro, reflecting its commitment to shaping the future of identity security through standards leadership and practical deployment. The company emphasizes the importance of moving beyond static authentication towards more dynamic and interoperable identity security systems, addressing the gaps left by traditional methods that rely on one-time authentication and long-lived access. By utilizing open standards like the OpenID Shared Signals Framework (SSF) and the Continuous Access Evaluation Profile (CAEP), CrowdStrike facilitates the seamless sharing of security and identity signals across different systems, enabling real-time adaptation to changing conditions. This approach allows for continuous evaluation and refinement of access, reducing reliance on standing privileges and minimizing security risks. Additionally, CrowdStrike's Falcon platform leverages these standards to enhance security intelligence sharing, connecting threat detection directly to identity enforcement. The company's involvement with IDPro and its support for the practitioner community ensure that emerging standards are practical and ready for real-world application, fostering a more connected and resilient identity landscape.
Jun 10, 2026
1,821 words in the original blog post.
CrowdStrike's June 2026 Patch Tuesday report highlights Microsoft's patching of 206 vulnerabilities, including three publicly disclosed zero-day vulnerabilities and numerous critical vulnerabilities affecting various Windows components and applications. This release addresses significant security flaws in systems such as Windows Kernel, Azure Kubernetes Service, and Remote Desktop Client, among others, with CVSS scores indicating high severity and potential risks of remote code execution and privilege escalation. Microsoft has proactively remediated some vulnerabilities within its cloud infrastructure without customer intervention, while CrowdStrike emphasizes the importance of a comprehensive security strategy that includes both patching and mitigation strategies for unpatchable vulnerabilities. The report underscores the ongoing effort to prioritize and manage cyber threats effectively through tools like CrowdStrike Falcon's Exposure Management, which helps organizations identify and address vulnerabilities efficiently.
Jun 09, 2026
4,728 words in the original blog post.
The CrowdStrike 2026 Technology Threat Landscape Report highlights the increasing threats faced by the technology sector from state-sponsored and eCrime adversaries, with a particular focus on China-nexus and DPRK-nexus actors. China-nexus adversaries, such as MURKY PANDA and SUNRISE PANDA, accounted for over 58% of state-sponsored intrusions, driven by the Chinese Communist Party's goals to achieve technological self-sufficiency and competitive advantage. These adversaries target tech organizations to access downstream customer environments and supply chains. Meanwhile, DPRK adversaries, including FAMOUS CHOLLIMA, focus on financial gain through fraudulent employment and supply chain compromises. The report also underscores the prevalence of eCrime activities, with big game hunting adversaries targeting North American tech entities for extortion, exploiting the rise in AI adoption for distributing malware. CrowdStrike's report provides insights into the evolving threat landscape and emphasizes the importance of tech organizations being vigilant and prepared to strengthen their defenses against these sophisticated adversaries.
Jun 09, 2026
1,800 words in the original blog post.
CrowdStrike and Zscaler have announced a strategic partnership to enhance security through the integration of CrowdStrike's Continuous Identity approach with Zscaler's Zero Trust Exchange, enabling real-time, risk-based access decisions. This collaboration aims to combat modern identity-driven cyber threats by providing comprehensive visibility and context across various domains, such as identity, endpoint, cloud, and SaaS applications, allowing for automatic threat detection and response. By utilizing open standards like the OpenID Shared Signals Framework and Continuous Access Evaluation Profile, the integration facilitates seamless interoperability and adaptive access management, helping organizations dynamically restrict access to sensitive resources and prevent lateral movement. This unified defense model promises to reduce security complexities and enhance protection against sophisticated cyber threats, aligning with the shared vision of both companies to stop attacks before they result in breaches.
Jun 08, 2026
1,783 words in the original blog post.
Autonomous AI agents are revolutionizing enterprise operations by moving beyond experimental phases to execute tasks and make decisions autonomously, yet they pose significant security challenges due to their capacity to interact with identities, APIs, workloads, and data. As these AI agents become integral to enterprise environments, traditional security models struggle to keep up, necessitating a secure-by-design approach that integrates security measures from the development phase through deployment and into runtime operations. Key principles for safely scaling agentic AI include treating AI agents as privileged identities by enforcing least-privilege access and continuous monitoring, securing the entire AI lifecycle to protect against vulnerabilities in live environments, and leveraging AI-driven analytics to counter AI-powered threats. By embedding security into AI systems, organizations can confidently scale their AI capabilities while minimizing risks, thereby transforming their operations and staying ahead of adversaries who exploit machine speed to automate attacks and evade detection.
Jun 05, 2026
1,670 words in the original blog post.
As organizations increasingly adopt AI systems, the complexity of managing data security is rising due to the continuous access, transformation, and movement of sensitive data across cloud services, APIs, and AI pipelines. ISO 42001:2023, the first international standard for AI management systems, offers a framework for the governance and monitoring of AI systems throughout their lifecycle, emphasizing the need for understanding data flows, assessing risks, and ensuring accountability. CrowdStrike's Falcon Data Security for Cloud provides critical visibility into data movement within cloud and AI environments, aiding organizations in tracing data origins, monitoring runtime activity, and identifying emerging risks. This tool supports key areas of ISO 42001:2023 by enhancing data governance, monitoring, and incident response capabilities, thereby helping organizations to better manage AI-related data risks and align with compliance requirements.
Jun 04, 2026
2,158 words in the original blog post.
AI is transforming the workplace by automating tasks and enhancing productivity, but it also introduces significant data loss risks if used carelessly or without sufficient security measures. Employees may inadvertently share sensitive information with AI systems, leading to potential breaches of confidentiality or compliance violations. Traditional security approaches, like endpoint security and legacy data loss prevention tools, are inadequate for managing AI-specific risks, as they often fail to monitor non-file-based interactions and react only after breaches occur. CrowdStrike's Falcon platform addresses these challenges by offering real-time monitoring of AI interactions within browsers, context-aware policy enforcement, and proactive threat detection to prevent data loss. This solution enables organizations to leverage AI's benefits while safeguarding sensitive information, ensuring a balance between security and productivity. As AI continues to evolve, businesses must adopt modern security strategies, educate employees on data protection risks, and regularly review policies to mitigate emerging threats effectively.
Jun 02, 2026
1,910 words in the original blog post.
CrowdStrike, in collaboration with NVIDIA, is enhancing security measures for AI-driven environments by integrating NVIDIA's DOCA Argus telemetry into the Falcon Next-Gen SIEM platform. This partnership focuses on providing comprehensive security for the AI factory, which requires continuous and unified protection across distributed systems. The integration aims to extend visibility and protection into the infrastructure layer, allowing security teams to identify and respond to threats more efficiently by correlating infrastructure-level signals with broader endpoint, identity, cloud, and data activities. By embedding real-time security features directly into the AI infrastructure, such as NVIDIA's Vera BlueField-4 STX, CrowdStrike and NVIDIA are working to ensure that as agentic AI scales, security measures scale alongside it. This approach not only enhances threat detection but also automates response workflows through CrowdStrike’s Charlotte Agentic SOAR, helping organizations manage security threats at machine speed without relying solely on perimeter defenses.
Jun 01, 2026
1,750 words in the original blog post.
CrowdStrike is enhancing its Falcon Exposure Management platform by integrating AI-native agents with NVIDIA technologies to improve vulnerability management at an enterprise scale. This collaboration aims to accelerate the identification, prioritization, and remediation of vulnerabilities through machine-speed reasoning and continuous exposure visibility, leveraging the vast security telemetry data collected by CrowdStrike. The AI agents are designed to provide dynamic risk reduction by correlating exploitability signals, asset criticality, and adversary behavior, moving beyond traditional scan-and-ticket workflows. This initiative underscores the importance of acting quickly and intelligently to mitigate risks as adversaries use AI to exploit vulnerabilities independently and at machine speed. By collaborating with NVIDIA, CrowdStrike seeks to empower security teams to operate at the speed required by the evolving threat landscape, ensuring that vulnerability management is both efficient and effective.
Jun 01, 2026
2,021 words in the original blog post.
CrowdStrike is advancing its security solutions by introducing AI Discovery and Governance capabilities for its Falcon platform, aimed at helping organizations manage AI technologies across enterprise environments. As AI integration expands, often without centralized tracking, this new feature provides visibility into AI tools, local models, SDKs, and external service integrations, addressing the emerging threat of shadow AI, which includes unsanctioned tools and models operating on endpoints. The AI Discovery and Governance feature enables security teams to identify unauthorized AI tools, enforce policies, and manage AI adoption without losing control of critical infrastructure. By mapping AI technologies to their capabilities, the platform allows organizations to govern AI at a functional level, enhancing visibility into sensitive data and credentials, thus reducing the enterprise attack surface. This development is part of CrowdStrike's broader effort to secure the AI-driven control plane, ensuring safe and scalable operations across enterprise and AI-enabled systems, with the Falcon platform offering a unified approach to manage and mitigate risks associated with AI technologies.
Jun 01, 2026
1,991 words in the original blog post.