CrowdStrike: cybersecurity giant behind global outage

A Crowdstrike office is shown in Sunnyvale, Calif., US. (AP)
Short Url
Updated 19 July 2024
Follow

CrowdStrike: cybersecurity giant behind global outage

  • The company’s share price was down by about 12 percent on Wall Street on Friday

WASHINGTON: CrowdStrike, the cybersecurity company behind a massive global IT outage, is the leader in its sector, known for building software defenses for the cloud computing age and exposing Russian and North Korean threats.
Based in Austin, Texas, the company was founded in 2011 by George Kurtz, Dmitri Alperovitch and Gregg Marston.
Both Kurtz and Alperovitch had extensive backgrounds in cybersecurity, working at companies like McAfee.
Two years after its founding, CrowdStrike launched its signature product, the Falcon platform.
Crucially, the company embraced a “cloud-first” model to reduce big computing needs on customers and provide more effective protection.
In particular, remote computing enables updates to be carried out quickly and regularly, something that failed spectacularly in Friday’s outage when an update proved incompatible with computers running on Microsoft software.
Rather than just focusing on malware and antivirus products, the founders wanted to shift attention to identifying and stopping the attackers themselves and their techniques.
“CrowdStrike is one of the best-known cybersecurity companies around,” said Michael Daniel, who worked as the White House cybersecurity coordinator during the Barack Obama administration.
“It provides typically what we think of as sort of endpoint protection, meaning that it’s actually got software running on a server, or on a particular device, like a laptop or a desktop, and it’s scanning for potential malware connections to bad domain names,” he said.
“It’s looking for behavior that might be unusual — that sort of thing,” said Daniel, who now runs the Cyber Threat Alliance.
A report published this year by CrowdStrike estimates that 70 percent of attacks do not include viruses, but were rather manipulations carried out directly by hackers, who often use stolen or recovered credentials.
The company’s share price was down by about 12 percent on Wall Street on Friday.
CrowdStrike became a publicly traded company in 2019, and in 2023 the group generated sales of $3.05 billion, up 36 percent year-on-year.
Boosted by the wave of so-called generative AI, which requires the development of additional capabilities in the cloud, CrowdStrike raised its annual forecasts in June.
Although its business has been booming, the group is still struggling with profitability.
In 2023, it recorded a net profit of just $89 million, its first annual profit since its creation.
The company’s main competitors are Palo Alto Networks and SentinelOne, both standalone cybersecurity firms.
But cloud computing giants Microsoft, Amazon and Google provide their own cybersecurity software and are also rivals.
CrowdStrike, which is also a cyber intelligence company, made headlines when it helped investigate several high-profile cyberattacks.
Most famously, in 2014, CrowdStrike discovered evidence linking North Korean actors to the hacking of servers at Sony Pictures.
The hackers stole large amounts of data and threatened terrorist acts against movie theaters to prevent the release of “The Interview,” a comedy about North Korea’s leader.
The studio initially canceled the movie’s theatrical release, but reversed its decision after criticism.
Sony estimated the direct costs of the hack to be $35 million for investigating and remediating the breach.
CrowdStrike also helped investigate the 2015-2016 cyberattacks on the Democratic National Committee (DNC) in the United States and their connection to Russian intelligence services.
In December 2016, CrowdStrike released a report stating that a Russian government-affiliated group called Fancy Bear had hacked a Ukrainian artillery app, potentially causing significant losses to Ukrainian artillery units in their fight against Moscow-backed separatists.
However, this assessment was later disputed by some organizations and CrowdStrike rolled back some of the claims.
In recent months, CrowdStrike has criticized Microsoft for its lapses on cybersecurity as the Windows maker admitted to vulnerabilities and hackings by outside actors.
Among other criticisms, CrowdStrike slammed Microsoft for still doing business in China.
“You’re telling the public they can’t use Huawei, and they can’t let kids watch dance videos on TikTok because China is going to collect intelligence,” Shawn Henry, chief security officer at CrowdStrike, said last year.
“Yet, the most ubiquitous software, which is used throughout the government and throughout every single corporation in this country and around the world, has engineers in China working on their software,” Henry told Forbes.


Man suspected in apparent assassination attempt on Trump charged with federal gun crimes

Updated 55 min 36 sec ago
Follow

Man suspected in apparent assassination attempt on Trump charged with federal gun crimes

  • Ryan Wesley Routh, 58, faces charges of possessing a firearm despite being a convicted felon and possessing a firearm with an obliterated serial number
  • Additional and more serious charges are possible as the investigation continues and prosecutors seek an indictment from a grand jury

FLORIDA: A man suspected in an apparent assassination attempt targeting former President Donald Trump was charged Monday with federal gun crimes, making his first court appearance in the final weeks of a White House race already touched by violence.
Ryan Wesley Routh, 58, faces charges of possessing a firearm despite being a convicted felon and possessing a firearm with an obliterated serial number. Additional and more serious charges are possible as the investigation continues and prosecutors seek an indictment from a grand jury.
Routh appeared briefly in federal court in West Palm Beach, where he answered perfunctory questions about his work status and income. Shackled and wearing a blue jumpsuit, he smiled as he spoke with a public defender and reviewed documents ahead of his initial appearance. The lawyer declined to comment after the court appearance.
The episode occurred Sunday afternoon when Secret Service agents stationed a few holes up from where Trump was playing golf noticed the muzzle of an AK-style rifle sticking through the shrubbery that lines the course, roughly 400 yards away.
An agent fired and Routh dropped the rifle and fled in an SUV, leaving the firearm behind along with two backpacks, a scope used for aiming and a GoPro camera, authorities said. Routh was later stopped by law enforcement in a neighboring county.
It was the second apparent assassination attempt targeting Trump in as many months.
On July 13, a bullet grazed Trump’s ear during a rally in Butler, Pennsylvania. Eight days later, Democratic President Joe Biden withdrew from the race, giving way for Vice President Kamala Harris to become the party’s nominee.


Germany wants trade with Kazakhstan, won’t circumvent Russia sanctions, Scholz says

Updated 16 September 2024
Follow

Germany wants trade with Kazakhstan, won’t circumvent Russia sanctions, Scholz says

  • “I am grateful for the trusting dialogue between us, through which we want to prevent trade between us from being misused to circumvent sanctions,” Scholz said
  • Both Scholz and Kazakh President Kassym-Jomart Tokayev said their countries were interested in increasing trade in oil, rare earths, lithium and other raw materials

ASTANA: Germany is interested in expanding trade with Kazakhstan while also ensuring such trade is not used to circumvent EU sanctions on Russia, Chancellor Olaf Scholz said on a visit to the Central Asian nation.
“I am grateful for the trusting dialogue between us, through which we want to prevent trade between us from being misused to circumvent sanctions,” Scholz said.
After Russian forces invaded Ukraine in February 2022, the West imposed sweeping sanctions on Russia, prompting Moscow to seek circuitous routes for importing technology and goods.
Sources have told Reuters that Russian businesses seeking goods banned by the West sometimes procured them from companies based in neighboring Kazakhstan or other former Soviet nations. The Astana government has said it would abide by the sanctions.
Both Scholz and Kazakh President Kassym-Jomart Tokayev said their countries were interested in increasing trade in oil, rare earths, lithium and other raw materials.
“Both sides benefit from this exchange because it allows us to diversify our economies and make them more resilient,” Scholz said. “A very concrete example of this is the oil supplies from Kazakhstan, which helped us a lot after Russia failed as a supplier.”
The two met ahead of a broader meeting between Scholz and all five Central Asian leaders, an example of more active Western diplomacy in what has traditionally been Russia’s backyard.
Kazakhstan has already stepped in to replace Russia as the supplier of crude for Berlin’s Schwedt refinery. Scholz’s visit comes after Russian President Vladimir Putin threatened to curb sales of metals such as titanium to “unfriendly” nations.


Russia evacuates border villages in Kursk region

Updated 16 September 2024
Follow

Russia evacuates border villages in Kursk region

  • Moscow appears to be mounting a counter-offensive in the region
  • More than 150,000 people in the region have had to flee their homes since Kyiv’s offensive began on August 6

MOSCOW: Russia is evacuating a number of villages in the Kursk region close to the Ukrainian border, the local governor said on Monday, almost six weeks after Ukraine launched its surprise incursion.
Moscow appears to be mounting a counter-offensive in the region, claiming to have retaken at least a dozen villages from Ukraine’s control since last week.
Authorities have decided to order the “obligatory evacuation of settlements in the Rylsky and Khomutovsky districts that are within a 15-kilometer (nine-mile) zone adjacent to the border with Ukraine,” Governor Alexei Smirnov said on Telegram.
He did not say which villages would be evacuated or the number of evacuees. There are dozens of villages and towns within this 15-kilometer radius.
More than 150,000 people in the region have had to flee their homes since Kyiv’s offensive began on August 6, state media reported Smirnov as saying last week.
Ukraine says its forces have advanced across tens of kilometers of Russian territory and seized dozens of settlements, including the border town of Sudzha.
Ukraine’s incursion — which began more than two years after Russia launched a full-scale military assault on its neighbor — caught Moscow off-guard.
It is the biggest incursion by a foreign army on Russian territory since World War II.


Secret Service ‘needs more help’ after apparent Trump assassination bid: Biden

Updated 16 September 2024
Follow

Secret Service ‘needs more help’ after apparent Trump assassination bid: Biden

  • “The (secret) service needs more help, and I think the Congress should respond to their needs,” Biden told reporters at the White House

WASHINGTON: President Joe Biden said Monday that the US Secret Service needs more personnel to perform its duties after a second apparent assassination attempt against Republican election candidate Donald Trump.
“One thing I want to make clear, the (secret) service needs more help, and I think the Congress should respond to their needs,” Biden told reporters at the White House.
“I think we may need more personnel.”
Biden added that “thank God the president’s OK” following Sunday’s incident in which the Secret Service opened fire on a gunman, who was later arrested, at Trump’s golf course in Florida.


Taliban have suspended polio vaccination campaigns in Afghanistan, UN says

Updated 59 min 41 sec ago
Follow

Taliban have suspended polio vaccination campaigns in Afghanistan, UN says

  • It comes as a setback for polio eradication, since the virus is one of the world’s most infectious 
  • Any unvaccinated groups of children where the virus is spreading could undo years of progress

DUBAI: The Taliban have suspended polio vaccination campaigns in Afghanistan, the UN said Monday. It’s a devastating setback for polio eradication, since the virus is one of the world’s most infectious and any unvaccinated groups of children where the virus is spreading could undo years of progress.

Afghanistan is one of two countries in which the spread of the potentially fatal, paralyzing disease has never been stopped. The other is Pakistan. It’s likely that the Taliban’s decision will have major repercussions for other countries in the region and beyond.

News of the suspension was relayed to UN agencies right before the September immunization campaign was due to start. No reason was given for the suspension, and no one from the Taliban-controlled government was immediately available for comment.

A top official from the World Health Organization said it was aware of discussions to move away from house-to-house vaccinations and instead have immunizations in places like mosques.

The WHO has confirmed 18 polio cases in Afghanistan this year, all but two in the south of the country. That’s up from six cases in 2023.

“The Global Polio Eradication Initiative is aware of the recent policy discussions on shifting from house-to-house polio vaccination campaigns to site-to-site vaccination in parts of Afghanistan,” said Dr. Hamid Jafari from the WHO. “Partners are in the process of discussing and understanding the scope and impact of any change in current policy.”

Polio campaigns in neighboring Pakistan are regularly marred by violence. Militants target vaccination teams and police assigned to protect them, falsely claiming that the campaigns are a Western conspiracy to sterilize children.

As recently as August, the WHO reported that Afghanistan and Pakistan were continuing to implement an “intensive and synchronized campaign” focusing on improved vaccination coverage in endemic zones and an effective and timely response to detections elsewhere.

During a June 2024 nationwide campaign, Afghanistan used a house-to-house vaccination strategy for the first time in five years, a tactic that helped to reach the majority of children targeted, the WHO said.

But southern Kandahar province, the base of Taliban supreme leader Hibatullah Akhundzada, used site-to-site or mosque-to-mosque vaccination campaigns, which are less effective than going to people’s homes.

Kandahar continues to have a large pool of susceptible children because it is not carrying out house-to-house vaccinations, the WHO said. “The overall women’s inclusion in vaccination campaigns remains around 20 percent in Afghanistan, leading to inadequate access to all children in some areas,” it said.

Any setback in Afghanistan poses a risk to the program in Pakistan due to high population movement, the WHO warned last month.

Pakistani health official Anwarul Haq said the polio virus would eventually spread and continue affecting children in both countries if vaccination campaigns aren’t run regularly and in a synchronized manner.

“Afghanistan is the only neighbor from where Afghan people in large numbers come to Pakistan and then go back,” said Haq, the coordinator at the National Emergency Operation Center for Polio Eradication. “People from other neighboring countries, like India and Iran, don’t come to Pakistan in large numbers.”

There needs to be a united effort to eliminate the disease, he told The Associated Press.

The campaign suspension is the latest obstacle in what has become a problematic global effort to stop polio. The initiative, which costs about $1 billion every year, has missed multiple deadlines to wipe out the disease and technical mistakes in the vaccination strategy set by WHO and partners have been costly.

The oral vaccine has also inadvertently seeded outbreaks in dozens of countries across Africa, Asia and the Middle East and now accounts for the majority of polio cases worldwide.

This was seen most recently in Gaza, where a baby was partially paralyzed by a mutated strain of polio first seen in the oral vaccine, marking the territory’s first case in more than 25 years.