• contact us
  • Home 1
  • Privacy Policy
Any News
ADVERTISEMENT
  • Home
  • Business
  • Crypto News
  • Finance
  • Health
  • Politics
  • Sports
  • Stock
  • Tech
  • Travel
No Result
View All Result
  • Home
  • Business
  • Crypto News
  • Finance
  • Health
  • Politics
  • Sports
  • Stock
  • Tech
  • Travel
No Result
View All Result
Any News
No Result
View All Result
Home Tech

The CrowdStrike fail and next global IT meltdown already in the making

admin by admin
July 21, 2024
in Tech
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


When computer screens went blue worldwide on Friday, flights were grounded, hotel check-ins became impossible, and freight deliveries were brought to a stand-still. Businesses resorted to paper and pen. And initial suspicions landed on some sort of cyberterrorist attack. The reality, however, was much more mundane: a botched software update from the cybersecurity company CrowdStrike.

“In this case, it was a content update,” said Nick Hyatt, director of threat intelligence at security firm Blackpoint Cyber.

And because CrowdStrike has such a broad base of customers, it was the content update felt around the world.

“One mistake has had catastrophic results. This is a great example of how closely tied to IT our modern society is — from coffee shops to hospitals to airports, a mistake like this has massive ramifications,”  Hyatt said.

In this case, the content update was tied to the CrowdStrike Falcon monitoring software. Falcon, Hyatt says, has deep connections to monitor for malware and other malicious behavior on endpoints, in this case, laptops, desktops, and servers. Falcon updates itself automatically to account for new threats.

“Buggy code was rolled out via the auto-update feature, and, well, here we are,”  Hyatt said. Auto-update capability is standard in many software applications, and isn’t unique to CrowdStrike. “It’s just that due to what CrowdStrike does, the fallout here is catastrophic,” Hyatt added.

The blue screen of death errors on computer screens are viewed due to the global communications outage caused by CrowdStrike, which provides cyber security services to US technology company Microsoft, on July 19, 2024 in Ankara, Turkey. 

Harun Ozalp | Anadolu | Getty Images

Even though CrowdStrike quickly identified the problem, and many systems were back up and running within hours, the global cascade of damage isn’t easily reversed for organizations with complex systems.

“We think three to five days before things are resolved,” said Eric O’Neill, a former FBI counterterrorism and counterintelligence operative and cybersecurity expert. “This is a bunch of downtime for organizations.”

It did not help, O’Neill said, that the outage happened on a summer Friday with many offices empty, and IT to help to resolve the issue in short supply. 

Software updates should be rolled out incrementally

One lesson from the global IT outage, O’Neill said, is that CrowdStrike’s update should have been rolled out incrementally.

“What Crowdstrike was doing was rolling out its updates to everyone at once. That is not the best idea.  Send it to one group and test it. There are levels of quality control it should go through,” O’Neill said.

“It should have been tested in sandboxes, in many environments before it went out,” said Peter Avery, vice president of security and compliance at Visual Edge IT.

He expects more safeguards are needed to prevent future incidents that repeat this type of failure.

“You need the right checks and balances in companies. It could have been a single person that decided to push this update, or somebody picked the wrong file to execute on,” Avery said.

The IT industry calls this a single-point failure — an error in one part of a system that creates a technical disaster across industries, functions, and interconnected communications networks; a massive domino effect. 

Call to build redundancy into IT systems

We need to make these systems 'a lot more resilient', says Cohesity CEO on global tech outages

Friday’s event could cause companies and individuals to heighten their level of cyber preparedness.

“The bigger picture is how fragile the world is; it’s not just a cyber or technical issue. There are a ton of different phenomena that can cause an outage, like solar flares that can take out our communications and electronics,” Avery said.

Ultimately, Friday’s meltdown wasn’t an indictment of Crowdstrike or Microsoft, but of how businesses view cybersecurity, said Javad Abed is an assistant professor of information systems at Johns Hopkins Carey Business School. “Business owners need to stop viewing cybersecurity services as merely a cost and instead as an essential investment in their company’s future,” Abed said.

Businesses should be doing this by building redundancy into their systems.

“A single point of failure shouldn’t be able to stop a business, and that is what happened,” Abed said. “You can’t rely on only one cybersecurity tool, cybersecurity 101,” Abed said.

While building redundancy into enterprise systems is costly, what happened Friday is more expensive.

“I hope this is a wake-up call, and I hope it causes some changes in the mindsets of the business owners and organizations to revise their cybersecurity strategies,” Abed said.

What to do about ‘kernel-level’ code

On a macro level, it is fair to assign some systemic blame within a world of enterprise IT that often views cybersecurity, data security, and the tech supply chain as “nice-to-have things” instead of essentials, and a general lack of cybersecurity leadership within organizations, said Nicholas Reese, former Department of Homeland Security official and instructor at New York University’s SPS Center for Global Affairs.

On a micro level, Reese said the code that caused this disruption was kernel-level code, impacting every computer hardware and software communication aspect. “Kernel-level code should get the highest level of scrutiny,” Reese said, with approval and implementation needing to be entirely separate processes with accountability.

That’s a problem that will continue for the entire ecosystem, awash in third-party vendor products, all with vulnerabilities.

“How do we look across the ecosystem of third-party vendors and see where the next vulnerability will be? It is almost impossible, but we have to try,” Reese said. “It is not a maybe, but a certainty until we grapple with the number of potential vulnerabilities. We need to focus on backup and redundancy and invest in it, but businesses say they can’t afford to pay for things that might never happen. It’s a hard case to make,” he said.

Tags: business newsCrowdStrikeCrowdStrike Holdings IncCybersecurityEnterprisefailGlobalmakingmeltdownSoftwareSuppress ZephrTechnology
Previous Post

Protocol Village: New ‘Smart Accounts’ From Cosmos-Based Osmosis Enable 1-Click Trading

Next Post

Barcelona protesters throw items and spray travelers with water while shouting ‘tourists go home’

Next Post

Barcelona protesters throw items and spray travelers with water while shouting 'tourists go home'

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected test

  • 137 Followers
  • 24k Followers
  • 99 Subscribers
ADVERTISEMENT
  • Trending
  • Comments
  • Latest

FAA to investigate Boeing after door plug falls off Alaska Airlines plane midair

January 11, 2024

Canadian government orders arbitration over Air Canada strike. Here’s what you need to know.

August 17, 2025

2 teens found dead in JetBlue landing gear ID’d months later with ‘extensive DNA testing’

April 9, 2025

ITC Hotels Q4 Results: Cons PAT jumps 19% YoY to Rs 257 crore; revenue rises 4%

May 15, 2025

Trump Endorses Jim Jordan in Race for House Speaker

0

A government shutdown wouldn’t stop air travel, but it could make it worse

0

Actor Bellamy Young opens up about her father’s chronic liver disease, hepatic encephalopathy

0

Bankman-Fried Seeks to Probe Lawyers’ Involvement in $200M ‘Sham’ Alameda Loans

0

Trump administration to send $500 payments to nearly 1 million Obamacare participants

September 13, 2026

Five dead after Amazon-branded cargo plane overruns runway at Miami airport, striking multiple vehicles

September 12, 2026

Adani Enterprises shares jump as airport unit enters into $1 billion fundraising deal

September 9, 2026

How Apple shares may react to the launch of first-ever foldable iPhone? Here’s what analysts say

September 9, 2026

Recent News

Trump administration to send $500 payments to nearly 1 million Obamacare participants

September 13, 2026

Five dead after Amazon-branded cargo plane overruns runway at Miami airport, striking multiple vehicles

September 12, 2026

Adani Enterprises shares jump as airport unit enters into $1 billion fundraising deal

September 9, 2026

How Apple shares may react to the launch of first-ever foldable iPhone? Here’s what analysts say

September 9, 2026

We bring the latest news from all over the world and get all time updated you

Follow Us

Browse by Category

  • Business
  • Crypto News
  • Finance
  • Health
  • Politics
  • Stock
  • Tech
  • Travel

Recent News

Trump administration to send $500 payments to nearly 1 million Obamacare participants

September 13, 2026

Five dead after Amazon-branded cargo plane overruns runway at Miami airport, striking multiple vehicles

September 12, 2026
  • contact us
  • Home 1
  • Privacy Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • contact us
  • Home 1
  • Privacy Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

  • bitcoinBitcoin(BTC)$29,407.000.01%
  • ethereumEthereum(ETH)$1,899.06-0.38%
  • tetherTether(USDT)$1.000.03%
  • binancecoinBNB(BNB)$324.28-0.81%
  • usd-coinUSD Coin(USDC)$1.000.08%
  • rippleXRP(XRP)$0.4814393.33%
  • cardanoCardano(ADA)$0.405927-0.39%
  • staked-etherLido Staked Ether(STETH)$1,898.54-0.41%
  • dogecoinDogecoin(DOGE)$0.0809211.05%
  • matic-networkPolygon(MATIC)$1.01-0.02%
  • solanaSolana(SOL)$23.394.99%
  • polkadotPolkadot(DOT)$6.001.05%
  • VectoriumVectorium(VECT)$425.81-3.49%
  • litecoinLitecoin(LTC)$90.051.19%
  • binance-usdBinance USD(BUSD)$1.000.08%
  • shiba-inuShiba Inu(SHIB)$0.0000100.77%
  • tronTRON(TRX)$0.0670861.88%
  • avalanche-2Avalanche(AVAX)$17.60-0.52%
  • daiDai(DAI)$1.000.14%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$29,424.000.04%
  • uniswapUniswap(UNI)$5.550.29%
  • chainlinkChainlink(LINK)$7.07-0.71%
  • cosmosCosmos Hub(ATOM)$11.732.47%
  • leo-tokenLEO Token(LEO)$3.530.50%
  • ftx-tokenFTX(FTT)$23.71-3.46%
  • ToncoinToncoin(TON)$2.15-2.59%
  • okbOKB(OKB)$47.860.12%
  • Bitcoin Cash ABCBitcoin Cash ABC(BCHA)$151.06-6.64%
  • ethereum-classicEthereum Classic(ETC)$19.931.15%
  • moneroMonero(XMR)$153.280.01%
  • internet-computerInternet Computer(ICP)$6.239.50%
  • stellarStellar(XLM)$0.0952070.67%
  • BitTorrentBitTorrent(BTT)$0.003681-1.64%
  • filecoinFilecoin(FIL)$5.502.23%
  • bitcoin-cashBitcoin Cash(BCH)$118.511.66%
  • true-usdTrueUSD(TUSD)$1.000.32%
  • AptosAptos(APT)$10.302.18%
  • crypto-com-chainCronos(CRO)$0.076702-0.56%
  • hedera-hashgraphHedera(HBAR)$0.0611050.34%
  • lido-daoLido DAO(LDO)$2.10-1.24%
  • ArbitrumArbitrum(ARB)$1.39-2.05%
  • nearNEAR Protocol(NEAR)$1.951.62%
  • quant-networkQuant(QNT)$114.671.23%
  • vechainVeChain(VET)$0.0225700.34%
  • apecoinApeCoin(APE)$4.050.25%
  • algorandAlgorand(ALGO)$0.1852130.99%
  • the-graphThe Graph(GRT)$0.139209-0.48%
  • fantomFantom(FTM)$0.4277530.63%
  • eosEOS(EOS)$1.052.20%
  • radixRadix(XRD)$0.109091-3.35%