Friday, July 19th 2024
Faulty Windows Update from CrowdStrike Hits Banks and Airlines Around the World
A faulty software update to enterprise computers by cybersecurity firm CrowdStrike has taken millions of computers offline, most of which are in a commercial or enterprise environment, or are Azure deployments. CrowdStrike provides periodic software and security updates to commercial PCs, enterprise PCs, and cloud instances, with a high degree of automation. The latest update reportedly breaks the Windows bootloader, causing bluescreens of death (BSODs), and if configured, invokes Windows Recovery. Enterprises tend to bulletproof the bootloaders of their client machines, and disable generic Windows Recovery tools from Microsoft, which means businesses around the world are left with large numbers of machines that will each take manual fixing. The so-called "Windows CrowdStrike BSOD deluge" has hit critical businesses such as banks, airlines, supermarket chains, and TV broadcasters. Meanwhile, sysadmins on Reddit are wishing each other a happy weekend.
Source:
The Verge
234 Comments on Faulty Windows Update from CrowdStrike Hits Banks and Airlines Around the World
Oh, I was sniped on this, lol.
For AMD there is DASH and AMC (AMD Management Console) supported by the PRO processors. You get remote access with KVM, USB ISO boot redirection, power control +++. As long as the device is connected to AC/DC or in modern standby and has a connection to the internet, you get access. Even when its powered of.
In this case, you could just use the boot redirect and fire up your favorite rescue ISO, like UBCD, Hirens etc. Just need to make sure you have the tools necessary for open/disable Bitfokker.
I used to be a sysadmin, and I have never missed doing it. But today I miss it even less.
One such example was a multibillion media company I worked which refused to allow the usage due to be “too chatty”
That was InfoSec and network team official response by the way.
So say what you will, but this is a huge issue for businesses that use CrowdStrike with Windows machines.
As mentioned above, user mode APIs for kernel events compared to a kernel driver does have a performance impact.
Yes, you could argue it's ultimately Microsoft's fault for not building a sufficiently isolated kernel, but that's very much ignoring the forest for the trees in this case.
The company now says it has found a solution to the problem.
“The problem has been identified, isolated and a solution implemented,” Crowdstrike CEO said.
Most companies these days bitlocker is on by default.