September 2026 Summaries
5 posts from Crowdstrike
Filter
Month:
Year:
Post Summaries
Back to Blog
No summary generated yet.
Sep 02, 2026
2,624 words in the original blog post.
No summary generated yet.
Sep 02, 2026
2,254 words in the original blog post.
No summary generated yet.
Sep 02, 2026
2,158 words in the original blog post.
CrowdStrike announced Falcon Guardian, an expansion of its AI Detection and Response offering designed to secure autonomous AI agents at runtime across endpoint, cloud, and SaaS environments. The platform combines agent discovery, governance, data protection, threat detection, investigation, and response, linking prompts, tool calls, identities, and agent activity to downstream operating-system behavior so teams can assess impact and contain malicious actions. New features include controls to identify shadow AI agents, restrict unauthorized agent types on managed Windows, macOS, and Linux endpoints, reconstruct agent sessions for investigations, and a planned AI gateway for centralized monitoring and policy enforcement of AI traffic. CrowdStrike is also extending its Adversary OverWatch threat hunting and Falcon Complete managed detection and response services to AI agents, while integrating agent telemetry with Falcon Next-Gen SIEM to support cross-domain analysis and potentially reduce third-party data-ingestion costs.
Sep 01, 2026
2,276 words in the original blog post.
CrowdStrike reported that, on August 31, 2026, it worked with U.S. and international law enforcement agencies and industry partners to disrupt Sality, a peer-to-peer botnet that had operated for more than two decades and distributed malware to over 15,000 infected systems worldwide. First identified in 2003, Sality spread by infecting executable files and relied on decentralized peer communications rather than centralized command-and-control servers, making it unusually persistent; its recent primary payload, EggJagger, replaced cryptocurrency wallet addresses copied to victims’ clipboards, with CrowdStrike estimating at least 12.1 million rubles in stolen cryptocurrency. The operation manipulated the botnet’s peer lists to remove legitimate nodes and introduce sinkholes, cutting the operator off from infected machines and preventing delivery of new payload instructions, while authorities also took down active payload-hosting URLs. CrowdStrike notes that the disruption does not remove existing malware from compromised devices and advises organizations to use the published network indicators, URLs, and YARA detection rules to identify and remediate remaining infections.
Sep 01, 2026
3,209 words in the original blog post.