Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CrowdStrike SafeMind: When the Best Offense Builds the Best Defense

The conventional approach to AI-powered security is to build an offensive agent to find weaknesses, build a defensive agent to catch threats, and run them in separate tracks. It's a clean division of labor that produces capable tools. However, the conventional approach also produces a permanent blind spot — the defense is never trained against the actual offense, and the connective tissue between the two is manual, slow, and fragile.

CrowdStrike Accelerates Real-Time Data Classification with On-Device AI

Modern data security depends on understanding sensitive data as it is created, accessed, and moved in real time directly on the endpoint. In addition to identifying predefined patterns such as credit card numbers or Social Security numbers, organizations must protect unstructured information including documents, chat logs, support tickets, AI prompts, medical records, and free-text fields.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software.

Preparing for an AI-Powered Future with Amazon CSO Steve Schmidt

Steve Schmidt, SVP and CSO at Amazon, sees firsthand how both defenders and adversaries are using AI to their advantage. In this episode, he joins Adam and Cristian to discuss modern AI models, evolving adversary behavior, and how Amazon is responding to shifts in the threat landscape. “The big change we’ve seen recently is the ability of models to chain things together to produce something interesting,” Steve says. As AI models grow more adept at automatically chaining and acting, he adds, the time to respond has dramatically decreased.

CrowdStrike Falcon Guardian: Secure AI Agents Where They Execute

CrowdStrike Falcon Guardian secures AI agents where they execute, delivering runtime visibility, governance and protection through the CrowdStrike Falcon platform. Falcon Guardian continuously discovers AI agents, connects AI activity to downstream endpoint execution for prompt-to-impact visibility, helps security teams investigate threats and determine blast radius, and enables response before threats spread. It also builds on proven AI security capabilities for Shadow AI discovery, AI governance, sensitive data protection and defense against AI-specific attacks.

CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day.

Falcon Next-Gen Identity Security: Agentic Identity Provider

CrowdStrike delivers the next evolution of the agentic SOC on the Falcon platform: coordinated teams of expert agents that investigate endpoint, identity, SaaS, cloud, and network domains simultaneously, converging on a single, evidence-backed verdict your team can trust.

CrowdStrike Delivers the Next Evolution of the Agentic SOC

The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time.

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.