CrowdStrike hires outside help to track down cause of global outages as it reveals first findings

Crowdstrike logo
(Image credit: Shutterstock / rafapress)

As CrowdStrike and its enterprise customers recover from the recent outage catastrophe, and it already being public knowledge that a pushed update caused the problem, the company has hired two security firms to look further into the issue.

The external code review was announced in a root causes analysis (PDF), while it was already known in the course of a post-incident review that a system designed to validate content (a ‘Content Validator’) failed to kick in, allowing a faulty IPS Template Instance intended to detect attacks to validate, causing crashes due to out-of-bounds memory reads.

CrowdStrike has announced it intends to mitigate similar broken update disruption in the future by staggering template deployment across devices, and that its content validator now has runtime bounds, preventing the same kind of memory issues from happening. It also intends to perform more internal testing, but only time will tell if this will have much material impact.

CrowdStruck (with a corporate lawsuit)

Even if you aren’t completely sure what a content validator is or how exactly memory reads can go above their station, you can probably imagine that a phased update rollout system sounds like a good idea for a company with software installed on millions of Windows PCs.

CrowdStrike’s shareholders have been thinking along the same lines, and have already filed a class-action lawsuit against the company for failing to implement such a system. Delta, meanwhile, are suing on the basis of lost revenue over a six-day period - which CrowdStrike say, perhaps with good reason, is Delta’s fault, actually,

Then again, it also said, about the shareholders case, that it believes the case ‘lacks merit’, and it’s hard to argue that one given that the implementation, or lack thereof, of a rolling patch system, lies entirely at CrowdStrike’s feet.

Via The Register

More from TechRadar Pro

Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
Crowdstrike logo
CrowdStrike claws back market value after triggering largest IT outage in history
Internet outage
Nearly all companies expect a major outage in 2025
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Eu
Is your business ready for DORA? Cisco ThousandEyes outlines the "three pillars" everyone needs to have in place to be resilient
Latest in Pro
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Racks of servers inside a data center.
Modernizing data centers: an efficient path forward
Dr. Peter Zhou, President of Huawei Data Storage Product Line
Why AI commonization is so important for business intelligent transformation and what Huawei’s data storage has to offer
Wix automation
The world's leading website builder aims to save businesses time with new tool
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over