Friday, July 19th 2024
Faulty Windows Update from CrowdStrike Hits Banks and Airlines Around the World
A faulty software update to enterprise computers by cybersecurity firm CrowdStrike has taken millions of computers offline, most of which are in a commercial or enterprise environment, or are Azure deployments. CrowdStrike provides periodic software and security updates to commercial PCs, enterprise PCs, and cloud instances, with a high degree of automation. The latest update reportedly breaks the Windows bootloader, causing bluescreens of death (BSODs), and if configured, invokes Windows Recovery. Enterprises tend to bulletproof the bootloaders of their client machines, and disable generic Windows Recovery tools from Microsoft, which means businesses around the world are left with large numbers of machines that will each take manual fixing. The so-called "Windows CrowdStrike BSOD deluge" has hit critical businesses such as banks, airlines, supermarket chains, and TV broadcasters. Meanwhile, sysadmins on Reddit are wishing each other a happy weekend.
Source:
The Verge
234 Comments on Faulty Windows Update from CrowdStrike Hits Banks and Airlines Around the World
At least then it turns out to be useful....
And yes, many critical tasks already run under some form of Linux, sure. But there are things where it isn’t feasible. MS isn’t the ones who contract this firm, no. Where did you even infer it?
Prayers for admins dealing with this and especially those that have to manually access bitlocker encypted machines one by one. If they have the keys.
This is a good point, actually. Good practice is to not roll shit out before weekends or, god forbid, long holidays. But maybe there was some rapid response fix or vulnerability protection they felt needed to be applied ASAP. Who even knows, at this point.
www.racefans.net/2024/07/19/global-crowdstrike-outage-leaves-mercedes-fixing-computers-before-practice/
I have known it to wreck things before (Personally saw this happen at work one morning from an overnight forced update / Win 10 no less) and lead to downtime and all the rest you'd expect.
Regardless of that, it's a major screwup and the fallout will certainly cause some heads to roll wherever.
I also feel for the IT guys having to address this because you know some are clocking in and just learning about it and that would include the boss..... Depending on the boss and the sheer number of machines affected wherever they are, it may be a really bad & long day for those guys.
On another note, this is why I insist most software I install will edit my my boot loader. Or at least they install some kernel-level shenanigans (looking at you anti-cheats). /s
The fix can only be done manually from recovery mode. This will take days to weeks to repair at scale.
It's the people who's keys are also on crashed servers that are most FUBAR. Even if they have them somewhere, have to manually do it all. If no keys, guess it's time to restore from backups.
"There was an outage confined in central US datacenters but it was resolved hours before crowdstrike shat its pants"
Besides even without the effort is equivalent since we use LAPS.
Although ... isn't there a thing called Intel Management Engine, which system admins can use to access disks and everything on a PC even if it's turned off or unable to boot?