[bt_bb_section layout=\”boxed_1200\” lazy_load=\”yes\” allow_content_outside=\”no\” show_video_on_mobile=\”\” bb_version=\”5.0.1\”][bt_bb_row][bt_bb_column order=\”0\” lazy_load=\”yes\” bb_version=\”5.0.1\” width=\”1/1\” width_xl=\”1/1\” width_lg=\”1/1\” width_md=\”1/1\” width_sm=\”1/1\” width_xs=\”1/1\”][bt_bb_text bb_version=\”5.0.1\” ai_prompt_helper=\”eyJrZXl3b3JkcyI6IiIsInRvbmUiOiIiLCJtb2RlIjoiZ2VuZXJhdGUiLCJsYW5ndWFnZSI6IiIsImxlbmd0aCI6IiJ9\”]
On July 19, 2024, businesses around the world experienced significant disruptions to their Windows workstations due to a faulty update from cybersecurity company CrowdStrike. This unexpected glitch caused widespread operational issues and highlighted the importance of reliable cybersecurity measures.
“Cybersecurity firm CrowdStrike has affected Microsoft Windows updates due to a faulty update in their software, causing a major worldwide outage,” said TNTMAX President and CIO Frederic Farcy. “This type of cybersecurity vulnerability is a direct result of faulty software updates, not a hack! Businesses face significant cybersecurity vulnerabilities, and their impact can have a global reach, as we are experiencing today. Be prepared and know that you are not immune—no one is.”
What Happened?
CrowdStrike released an update that inadvertently triggered Blue Screens of Death (BSOD) on Windows hosts, The Hacker News reported. The company clarified that the issue was due to a defect in the update and was not a result of a security breach or cyberattack. Mac and Linux systems were not affected.
The faulty update caused Windows virtual machines (VMs) on platforms like Google Cloud Compute Engine and Microsoft Azure to crash, requiring multiple reboots to restore functionality. Amazon Web Services (AWS) also reported similar issues and took immediate steps to mitigate the problem.
Immediate Response and Fix
CrowdStrike quickly identified the issue and deployed a fix for its Falcon Sensor product. Affected customers were advised to follow these steps to mitigate the problem:
- Boot Windows in Safe Mode or Windows Recovery Environment.
- Navigate to the C:\\Windows\\System32\\drivers\\CrowdStrike directory.
- Delete the file named \”C-00000291*.sys\”.
- Restart the computer or server normally.
Despite these efforts, the recovery process is expected to take several days as each endpoint needs to be manually addressed.
Impact and Implications
The incident disrupted a wide range of businesses, including airlines, financial institutions, retail chains, hospitals, hotels, news organizations, railway networks, and telecom firms. The widespread impact caused CrowdStrike\’s shares to drop by 15% in U.S. premarket trading.
Lessons Learned
This event underscores the importance of implementing multiple fail-safes and diversifying IT infrastructure. Small errors in updates and maintenance can have extensive repercussions. There is a need for diversity in IT systems to mitigate the risks associated with single points of failure.
The CrowdStrike update incident is a cautionary tale for businesses and cybersecurity professionals alike. It highlights the need for meticulous testing and gradual rollout of updates, especially in systems with high privileges. As the recovery process unfolds, understanding the root cause of the malfunction and preventing similar incidents in the future will be crucial.
[/bt_bb_text][/bt_bb_column][/bt_bb_row][/bt_bb_section]



