Recent Blogs
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applicatio[…]
Falcon AIDR Now Protects Copilot Studio Agents and Claude Code
Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can exp[…]
Inside Astaroth's New Spambot Component
Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against targe[…]
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud
Every change in a cloud environment creates new security decisions. A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release int[…]
Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats
Organizations face a relentless stream of emerging threats, from zero-day exploits to rapidly evolving adversary tactics. They need protection that keeps pace with this changing landscape without addi[…]
5 High-Impact Use Cases for Falcon Onum
Security teams have never had more tools or more data problems. SIEMs, data lakes, threat intelligence platforms, observability tools, compliance archives, and AI engines all promise better outcomes, […]
CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security
AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders[…]
CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, which transforms federal vulnerability management by shifting agencies from st[…]
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two u[…]
Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense
Frontier AI is fundamentally changing the pace of cybersecurity. For defenders and adversaries alike, it compresses the time required to discover vulnerabilities, assess exploitability, and act. AI mo[…]