Home / Companies / Crowdstrike / Blog / August 2026

August 2026 Summaries

4 posts from Crowdstrike

Filter
Month: Year:
Post Summaries Back to Blog
CrowdStrike research finds that VMware ESX hypervisors, frequent ransomware targets, can support far more shell-command obfuscation than expected despite their minimal BusyBox environment, enabling attackers to conceal actions such as virtual-machine discovery, syslog tampering, and command execution from keyword-based log detections. Researchers validated 21 techniques across six categories, including escape-sequence encoding, dynamic character generation, invisible Unicode injection, cryptographic and infrastructure-derived decoding keys, VMFS-based steganography, and alternative representations such as Morse code, binary, and scientific notation. Because ESX shell logs capture commands before shell expansion, obfuscated commands may execute normally while leaving no recognizable malicious keywords in telemetry. CrowdStrike developed regex-based CrowdStrike Query Language patterns and a Falcon Next-Gen SIEM correlation rule to identify shared syntactic indicators across these techniques, mapping the activity to relevant MITRE ATT&CK methods and supplementing a broader library of VMware detection rules. The research emphasizes establishing a baseline of normal plaintext ESX administration activity and using centralized telemetry, continuous asset visibility, and proactive threat hunting to detect evasive behavior before attackers operationalize it.
Aug 07, 2026 3,896 words in the original blog post.
CrowdStrike argues that AI cybersecurity evaluation should extend beyond vulnerability discovery and exploit generation, which are easy to measure but address only one route into an organization, noting that vulnerability exploitation accounted for 31% of breaches in Verizon’s 2026 dataset while credential abuse, phishing, social engineering, and trusted relationships remain major entry points. It contends that meaningful assessments should test whether AI can support the broader defensive lifecycle, including alert triage, investigation, detection engineering, threat hunting, remediation, and response after attackers gain access. The company says public benchmarks are limited by their focus on creator priorities, score saturation among leading models, potential training-data contamination, and insufficient connection to real-world telemetry and adversary tradecraft. It proposes task-relevant, telemetry-grounded, customer-specific evaluations using real intrusion intelligence and organizational threat profiles, and states that it plans to demonstrate this approach at Fal.Con 2026.
Aug 06, 2026 2,211 words in the original blog post.
CrowdStrike employs a robust defense-in-depth architecture comprising seven independent control layers to ensure the secure execution of autonomous AI agents, preventing them from taking unintended actions. This approach involves a combination of infrastructure isolation, virtual machine containment, OS-level controls, and process capability confinement, each functioning independently to address potential containment failures. The framework is designed to handle various tasks, such as vulnerability discovery and adversarial emulation, while preventing unauthorized agent behaviors like data exfiltration and host compromise. By treating agents as untrusted code and implementing rigorous testing and validation procedures, CrowdStrike aims to advance the secure deployment of AI within cybersecurity workflows. The secure-by-design architecture ensures that agent actions are confined within controlled boundaries, with human-in-the-loop escalation for certain sensitive operations, ensuring a comprehensive audit trail and maintaining operational integrity. As AI capabilities evolve, CrowdStrike continues to refine these safeguards, ensuring they remain effective against increasingly sophisticated threats.
Aug 04, 2026 4,290 words in the original blog post.
The CrowdStrike 2026 Threat Hunting Report highlights the evolving landscape of cybersecurity threats, with an emphasis on the increasing exploitation of trusted relationships and AI tools by adversaries. The report details how attackers are targeting identity systems, cloud environments, SaaS applications, and developer workflows to access critical assets before detection. Notably, AI has become both a tool and a target for adversaries, leading to more complex challenges for defenders. The report documents rapid exploitation of vulnerabilities, with adversaries acting within hours of public disclosures, and significant software supply chain attacks, particularly in open-source ecosystems. Noteworthy incidents include the use of AI-centric environments by DPRK-affiliated FAMOUS CHOLLIMA for sophisticated attacks on cryptocurrency firms and the exploitation of npm packages by adversaries like STARDUST CHOLLIMA. CrowdStrike's ongoing efforts to track and analyze over 290 adversaries are crucial for understanding and mitigating these threats, and the report provides essential insights for organizations to enhance their defensive strategies.
Aug 03, 2026 1,905 words in the original blog post.