GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 16:03:47 JST Kevin Beaumont Kevin Beaumont

    Crowdstrike published a faulty update. Causes Windows to bluescreen. Driver is C-00000291*.sys. Will cause worldwide outages.

    In conversation Friday, 19-Jul-2024 16:03:47 JST from cyberplace.social permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 16:10:21 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I am obtaining a copy of the driver to see if malicious or bad coding, if anybody else checking let me know.

      In conversation Friday, 19-Jul-2024 16:10:21 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 16:14:34 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is wondering the impact of the Crowdstrike thing - it’s really bad. Machines don’t boot.

      The recovery is boot in safe mode, log in as local admin and delete things - which isn’t automateable. Basically Crowdstrike will be in very hot water.

      In conversation Friday, 19-Jul-2024 16:14:34 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 16:41:48 JST Kevin Beaumont Kevin Beaumont
      in reply to

      You know it was coming...

      Crowdstrike's BSOP theme tune

      In conversation Friday, 19-Jul-2024 16:41:48 JST permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 16:45:13 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Sky News has gone off air in the UK.

      In conversation Friday, 19-Jul-2024 16:45:13 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/812/035/052/540/095/original/9220b9cc5e8c5e85.png
    • Embed this notice
      ISO8601 (iso8601@cyberplace.social)'s status on Friday, 19-Jul-2024 16:50:27 JST ISO8601 ISO8601
      in reply to

      @GossiTheDog New order to Vanguard subs: "if Radio 4 is offline, please check a couple of other other radio stations to see whether it's an MS or AV outage. Ta."

      In conversation Friday, 19-Jul-2024 16:50:27 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 17:12:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Favour to IT folks fixing - could you please copy the C-00000291*.sys file to somewhere and upload it to Virustotal, and reply with the Virustotal link or file hash? It's still unclear if the update was malicious or just a bug.

      In conversation Friday, 19-Jul-2024 17:12:38 JST permalink
    • Embed this notice
      Lorenzo 'kelset' Sciandra (kelset@mastodon.online)'s status on Friday, 19-Jul-2024 17:21:12 JST Lorenzo 'kelset' Sciandra Lorenzo 'kelset' Sciandra
      in reply to

      @GossiTheDog at least according to the sources quoted here it seems not malicious: https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/comment/ldvwkbn/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

      (but just gross incompetence)

      In conversation Friday, 19-Jul-2024 17:21:12 JST permalink

      Attachments


    • Embed this notice
      Guelfo Alexander Ghibellini (guelfoalexander@cyberplace.social)'s status on Friday, 19-Jul-2024 17:25:57 JST Guelfo Alexander Ghibellini Guelfo Alexander Ghibellini
      in reply to

      @GossiTheDog sorry for posting a dumbser hint, but there is no way to batch a rolling back to Windows previous System Restore Point?

      In conversation Friday, 19-Jul-2024 17:25:57 JST permalink
    • Embed this notice
      mvyrmnd :PUA: (mvyrmnd@aus.social)'s status on Friday, 19-Jul-2024 17:26:35 JST mvyrmnd :PUA: mvyrmnd :PUA:
      in reply to

      @GossiTheDog https://www.virustotal.com/gui/file/ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362

      In conversation Friday, 19-Jul-2024 17:26:35 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        VirusTotal
        VirusTotal
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 17:42:18 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I've obtained copies of the .sys driver files Crowdstrike customers have. They're garbage. Each customer appears to have a different one.

      They trigger an issue that causes Windows to blue screen.

      I am unsure how these got pushed to customers. I think Crowdstrike might have a problem.

      In conversation Friday, 19-Jul-2024 17:42:18 JST permalink
      Haelwenn /элвэн/ :triskell: and kaia like this.
    • Embed this notice
      JP (froztbyte@mastodon.social)'s status on Friday, 19-Jul-2024 17:42:43 JST JP JP
      in reply to

      @GossiTheDog I don’t touch windows much at all these days, what particularly makes it non-automateable? I would’ve thought things like pxeboot’d scripted run envs or something could be viable, albeit that’s with a heavily *nix-background talking

      In conversation Friday, 19-Jul-2024 17:42:43 JST permalink
    • Embed this notice
      The Penguin of Evil (etchedpixels@mastodon.social)'s status on Friday, 19-Jul-2024 17:44:20 JST The Penguin of Evil The Penguin of Evil
      in reply to

      @GossiTheDog Are they signed garbage ?

      In conversation Friday, 19-Jul-2024 17:44:20 JST permalink
    • Embed this notice
      Xebulun EnEssEitch (xeb@chaos.social)'s status on Friday, 19-Jul-2024 17:56:26 JST Xebulun EnEssEitch Xebulun EnEssEitch
      • The Penguin of Evil

      @GossiTheDog @etchedpixels how do you know?

      In conversation Friday, 19-Jul-2024 17:56:26 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:14:06 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is wondering, the update was delivered via channel updates in Crowdstrike.

      In conversation Friday, 19-Jul-2024 18:14:06 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:15:41 JST Kevin Beaumont Kevin Beaumont
      in reply to

      BBC tracker (they mix up an earlier Microsoft outage, what they're actually tracking is the Crowdstrike issue) https://www.bbc.co.uk/news/live/cnk4jdwp49et

      In conversation Friday, 19-Jul-2024 18:15:41 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: static.files.bbci.co.uk
        IT outage live updates: Planes grounded as mass worldwide issue hits airlines, media and banks
        from https://www.facebook.com/bbcnews
        American Airlines says none of its flights are taking off, due to an issue with Crowdstrike cybersecurity software - Microsoft says it is taking "mitigation action".
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:31:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The .sys files causing the issue are channel update files, they cause the top level CS driver to crash as they're invalidly formatted. It's unclear how/why Crowdstrike delivered the files and I'd pause all Crowdstrikes updates temporarily until they can explain.

      This is going to turn out to be the biggest 'cyber' incident ever in terms of impact, just a spoiler, as recovery is so difficult.

      In conversation Friday, 19-Jul-2024 18:31:20 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:32:40 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike's shares are down 20% in pre-market.

      In conversation Friday, 19-Jul-2024 18:32:40 JST permalink
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:43:15 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I'm seeing people posting scripts for automated recovery.. Scripts don't work if the machine won't boot (it causes instant BSOD) -- you still need to manually boot the system in safe mode, get through BitLocker recovery (needs per system key), then execute anything.

      Crowdstrike are huge, at a global scale that's going to take.. some time.

      In conversation Friday, 19-Jul-2024 18:43:15 JST permalink
      Thomas 🔭🕹️ repeated this.
    • Embed this notice
      Bálint Szilakszi (szbalint@x0r.be)'s status on Friday, 19-Jul-2024 18:44:25 JST Bálint Szilakszi Bálint Szilakszi
      in reply to

      @GossiTheDog Crowdstrike / SOC managing Crowdstrike is saying that there is no possibility to pause these type of updates (we asked). “It would not have prevented this incident.”

      In conversation Friday, 19-Jul-2024 18:44:25 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 18:59:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Crowdstrike statement: https://www.bbc.co.uk/news/live/cnk4jdwp49et?post=asset%3A0c379e1f-48df-493c-a11a-f6b1e3d1eb63#post

      Basically 'it's not a security incident... we just bricked a million systems'

      In conversation Friday, 19-Jul-2024 18:59:00 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/812/556/140/081/824/original/e779df997be1d8dc.png
      2. Domain not in remote thumbnail source whitelist: static.files.bbci.co.uk
        IT outage live updates: Crowdstrike cybersecurity firm blames software update for worldwide IT chaos
        from https://www.facebook.com/bbcnews
        Major outages are hitting Microsoft users across the world, with airlines, shops and healthcare affected.
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Derek Robson (robsonde@mastodon.social)'s status on Friday, 19-Jul-2024 19:20:36 JST Derek Robson Derek Robson
      in reply to

      @GossiTheDog
      A million systems?

      29k customers, and assuming 5k boxes per customer == 145 million boxes.

      In conversation Friday, 19-Jul-2024 19:20:36 JST permalink
    • Embed this notice
      robwalker (robwalker@cyberplace.social)'s status on Friday, 19-Jul-2024 19:33:42 JST robwalker robwalker
      in reply to

      @GossiTheDog USB Rubber Ducky script? 😀 Oh, nope, BitLocker will prevent that being workable

      In conversation Friday, 19-Jul-2024 19:33:42 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 20:04:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      For anybody wondering why Microsoft keep ending up in the frame, they had an Azure outage and- this may be news to some people- a lot of Microsoft support staff are actually external vendors, eg TCS, Mindtree, Accenture etc.

      Some of those vendors use Crowdstrike, and so those support staff have no systems.

      But MS isn’t the outage cause today.

      In conversation Friday, 19-Jul-2024 20:04:56 JST permalink
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Friday, 19-Jul-2024 20:11:48 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog I dont know how to use this platform but you seem to. here is a semi automatic way that I solved this on 1000 machines in 30 minutes.

      Copy your custom drivered WinPE image (or a bare one from the ADK) to your system.
      Mount it with wimlib.
      Edit startnet.cmd and add
      del C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys
      exit

      unmount image
      put image in your PXE loader OR make it a usb bootable in Rufus

      Save an assload of time.

      In conversation Friday, 19-Jul-2024 20:11:48 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 20:16:21 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Crowdstrike publishes updated CIA triad

      In conversation Friday, 19-Jul-2024 20:16:21 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/812/866/945/099/230/original/e053c781d7593335.jpeg
    • Embed this notice
      uzayran (uzayran@cyberplace.social)'s status on Friday, 19-Jul-2024 20:17:31 JST uzayran uzayran
      in reply to

      @GossiTheDog "We can do it faster"

      In conversation Friday, 19-Jul-2024 20:17:31 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/812/865/217/637/399/original/31b3cd0f10bf4b00.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 21:39:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      By far my fave thing with the Crowdstrike thing is Microsoft saying to try turning impacted PCs off and on again in a loop until you get the magic reboot where CrowdStrike updates before it blue screens.

      In conversation Friday, 19-Jul-2024 21:39:20 JST permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 21:49:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      lol Microsoft have put ‘reboot each box 15 times’ on its website

      In conversation Friday, 19-Jul-2024 21:49:49 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/813/234/759/618/321/original/ed355e845bdafe88.jpeg
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 22:05:40 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The chuckle brothers at NoName attempting to claim they caused the incident. To be super clear, NoName can barely DDoS a bike shed website, and once asked me to make their logo in Minecraft.

      In conversation Friday, 19-Jul-2024 22:05:40 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/813/297/031/330/128/original/58de48cf88753f9a.jpeg
      Haelwenn /элвэн/ :triskell: repeated this.
    • Embed this notice
      Hyde 📷 🖋 :debian: (hyde@lazybear.social)'s status on Friday, 19-Jul-2024 22:22:33 JST Hyde 📷 🖋 :debian: Hyde 📷 🖋 :debian:
      in reply to

      @GossiTheDog Did they remove the link saying that ?

      In conversation Friday, 19-Jul-2024 22:22:33 JST permalink
    • Embed this notice
      eclectiqus (eclectiqus@cyberplace.social)'s status on Friday, 19-Jul-2024 22:28:07 JST eclectiqus eclectiqus
      in reply to

      @GossiTheDog
      What’s the chance that a low and slow piece of malware has been living in some windows recovery mode file system and this CS Falcon thing is just an impressive method for activating it across the global windows fleet of critical servers protected by CrowdStrike?

      In conversation Friday, 19-Jul-2024 22:28:07 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 22:45:15 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Probably the funniest BBC news update so far (they’ve cleared the airways for this incident).

      In conversation Friday, 19-Jul-2024 22:45:15 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/813/452/715/176/917/original/58327a5edd8b9f27.png
    • Embed this notice
      Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 19-Jul-2024 23:01:21 JST Ryan Castellucci (they/them) :nonbinary_flag: Ryan Castellucci (they/them) :nonbinary_flag:
      in reply to

      @GossiTheDog is it too late to buy calls?

      In conversation Friday, 19-Jul-2024 23:01:21 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jul-2024 23:34:08 JST Kevin Beaumont Kevin Beaumont
      in reply to

      🤪

      In conversation Friday, 19-Jul-2024 23:34:08 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/813/642/909/970/563/original/428c7d5fc13a28e0.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 02:11:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      BBC News at 6 is leading the entire show with this. (They asked me to appear but I was slightly busy).

      For the record I spent much of the day trying to tell people it isn’t a Microsoft issue.

      In conversation Saturday, 20-Jul-2024 02:11:28 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/814/263/551/152/151/original/232acea46a8342b5.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 03:36:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      When I get successfully DDoS’d it’s both a security incident and I’m not protected…

      In conversation Saturday, 20-Jul-2024 03:36:31 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/814/597/887/145/999/original/05e48fbe972d15e4.png
      Blurry Moon and Tim Chambers repeated this.
    • Embed this notice
      Eric Likness (carpetbomberz@mastodon.online)'s status on Saturday, 20-Jul-2024 03:43:58 JST Eric Likness Eric Likness
      in reply to

      @GossiTheDog Perspective, man. Depends on which end of the telescope you're looking thru. 🔭

      In conversation Saturday, 20-Jul-2024 03:43:58 JST permalink
    • Embed this notice
      Eric Likness (carpetbomberz@mastodon.online)'s status on Saturday, 20-Jul-2024 03:43:58 JST Eric Likness Eric Likness
      in reply to

      @GossiTheDog And I luv seeing George's accomplishments listed out here:

      `In his personal time, he is an avid exotic car collector and has driven Audi R8 LMS GT4 and Mercedes-AMG GT3[32] in the Pirelli World Challenge. Previously, he raced in the Radical Cup and Sports Car Club of America endurance events.[34] He is currently driving for CrowdStrike Racing.`

      https://en.wikipedia.org/wiki/George_Kurtz

      In conversation Saturday, 20-Jul-2024 03:43:58 JST permalink
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Saturday, 20-Jul-2024 04:18:29 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog People on CNBC were praising him because he used to be the CTO of McAfee.when McAfee did this exact same thing in 2010. Look it up. Seriously

      In conversation Saturday, 20-Jul-2024 04:18:29 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 04:38:34 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Billboards in Times Square blue screen of deathing. Nice way to find out which orgs use Crowdstrike, this 🤣

      In conversation Saturday, 20-Jul-2024 04:38:34 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/814/841/149/398/498/original/587782eac7ac7ce0.jpeg
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      lambtor (lambtor@cyberplace.social)'s status on Saturday, 20-Jul-2024 04:47:53 JST lambtor lambtor
      in reply to

      @GossiTheDog So peaceful.

      In conversation Saturday, 20-Jul-2024 04:47:53 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 04:57:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Crazy video of flights being ground stopped across the US earlier today, due to the CrowdStrike issue. https://www.bbc.co.uk/news/live/cnk4jdwp49et?post=asset%3Ae7676a84-628c-4830-ba22-3b86a0d7de4c#post

      In conversation Saturday, 20-Jul-2024 04:57:56 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/814/918/091/011/177/original/bfe76574b6a0e534.jpeg
      2. Domain not in remote thumbnail source whitelist: static.files.bbci.co.uk
        Microsoft IT outage live updates: Global IT chaos persists as Crowdstrike boss admits outage could take time to fix
        from https://www.facebook.com/bbcnews
        Airports, banking and healthcare were all hit when a Crowdstrike update triggered huge Microsoft outages.
      Joe Ortiz repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 05:00:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Photos of CrowdStrike issue https://www.theverge.com/24202037/microsoft-crowdstrike-outage-blue-screen-error-photos

      In conversation Saturday, 20-Jul-2024 05:00:20 JST permalink

      Attachments

      1. Blue Screen of Death photos from around the world
        from William Joel
        Some of the biggest error messages we’ve ever seen.
    • Embed this notice
      Guelfo Alexander Ghibellini (guelfoalexander@cyberplace.social)'s status on Saturday, 20-Jul-2024 05:36:19 JST Guelfo Alexander Ghibellini Guelfo Alexander Ghibellini
      in reply to

      @GossiTheDog https://www.tumblr.com/guelfoalexander/756464981458944000/attention-to-alternative-solutions-to-bypass-the?source=share

      In conversation Saturday, 20-Jul-2024 05:36:19 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Attention to alternative solutions to bypass the problem
        from Cav. Agilulfo
        The CERT continues to monitor the implications and impacts of the cyber incident that caused a massive outage of services and systems related to #Microsoft and #CrowdStrike this morning. ⚠️ It has…
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 05:56:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      *whispers* They work remotely on Friday

      In conversation Saturday, 20-Jul-2024 05:56:58 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/815/150/407/304/087/original/ce260d640cf72c93.jpeg
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Casey Smith (subtee@federate.social)'s status on Saturday, 20-Jul-2024 06:10:45 JST Casey Smith Casey Smith
      in reply to

      @GossiTheDog

      The stressed employees are in Maryland my dear.

      In conversation Saturday, 20-Jul-2024 06:10:45 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 18:19:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike have effectively a mini root cause analysis out

      Pretty much as everybody knows, they did a channel update and it caused the driver to crash.

      If they blame the person who did the update.. they shouldn’t, as it sounds like an engine defect.

      https://www.crowdstrike.com/blog/technical-details-on-todays-outage/

      In conversation Saturday, 20-Jul-2024 18:19:49 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.crowdstrike.com
        Technical Details on July 19, 2024 Outage | CrowdStrike
        from @CrowdStrike
        Learn more about the July 19, 2024 CrowdStrike outage and the technical details related to it.
    • Embed this notice
      Kieran McGuire (kieranmcguire@hachyderm.io)'s status on Saturday, 20-Jul-2024 19:06:05 JST Kieran McGuire Kieran McGuire
      in reply to

      @GossiTheDog Ed Zitron wrote a post that, amongst other things, says that it was a faulty *kernel driver* update and Microsoft is at least partially responsible for signing it. Would you say this is inaccurate? (Will be a shame if so, Ed’s work is usually pretty good!)

      In conversation Saturday, 20-Jul-2024 19:06:05 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 19:46:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      For the people thinking ‘shouldn’t testing catch this?’, the answer is yes. Clearly something went wrong.

      This isn’t CrowdStrike’s first rodeo on this, although it is the most severe incident so far.

      Eg just last month they had an issue where a content update pushed CPU to 100% on one core: https://www.thestack.technology/crowdstrike-bug-maxes-out-100-of-cpu-requires-windows-reboots/

      Truthfully these issues happen across all vendors - I’ve had my orgs totalled twice now by AV vendors, one while I was on holiday abroad and had to suspend said holiday.

      In conversation Saturday, 20-Jul-2024 19:46:35 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.thestack.technology
        CrowdStrike bug maxes out 100% of CPU, requires Windows reboots
        "Note: This is 100% of a single core. In an 8-core system for example, an additional 12.5% of unexpected total CPU load would be experienced..."
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jul-2024 19:52:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Btw, that isn’t to excuse it or any vendor. CrowdStrike have gotta be better at this stuff. And they’ll have to, as if they aren’t transparent customers will flee.

      It’s a warning shot to all AV/EDR/XDR vendors that if you fuck up availability, your brand will become failure. It’s harsh but that’s the media cycle and modern world.

      In conversation Saturday, 20-Jul-2024 19:52:35 JST permalink
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      WowSuchCyber (wowsuchcyber@toot.zof.sh)'s status on Saturday, 20-Jul-2024 19:53:10 JST WowSuchCyber WowSuchCyber
      in reply to

      @GossiTheDog they happened at McAfee in 2010

      In conversation Saturday, 20-Jul-2024 19:53:10 JST permalink
    • Embed this notice
      Raphael (0x3e4@cyberplace.social)'s status on Saturday, 20-Jul-2024 19:55:25 JST Raphael Raphael
      in reply to

      @GossiTheDog rememberberrie when MS defender killed all desktop shortcuts lmao.. last year?

      In conversation Saturday, 20-Jul-2024 19:55:25 JST permalink
    • Embed this notice
      I love this, so I (jpm@aus.social)'s status on Saturday, 20-Jul-2024 20:05:08 JST I love this, so I I love this, so I
      in reply to

      @GossiTheDog watch customers flee without understanding what they’re fleeing from: https://aus.social/@jpm/112812079293445696

      In conversation Saturday, 20-Jul-2024 20:05:08 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        /dev/rdsk/c5t1d0s2 (@jpm@aus.social)
        from /dev/rdsk/c5t1d0s2
        Companies rushing to uninstall CrowdStrike enterprise-wide because “it’s a risk”: very many Companies understanding that the exact same risk exists in every single Very Enterprise Security Software Tool: approximately zero
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Saturday, 20-Jul-2024 20:40:41 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog Also.. its 20% the Windows kernel having code from Win2k in it. Truth is Windows should never BSOD or allow something else to make it BSOD.

      In conversation Saturday, 20-Jul-2024 20:40:41 JST permalink
    • Embed this notice
      jmjm (jmjm@mstdn.social)'s status on Saturday, 20-Jul-2024 22:07:13 JST jmjm jmjm
      in reply to

      @GossiTheDog intended as a serious question, not snark:

      When I push a kernel update to prod I have a gradual rollout plan that lets me canary the change and roll it back, say, before the pager outside the CEOs hot tub goes off.

      Did Cloudstrike just not do that, or is there some technical reason (latency between deployment and failure) that this common strategy failed?

      In conversation Saturday, 20-Jul-2024 22:07:13 JST permalink
    • Embed this notice
      Khleedril (khleedril@cyberplace.social)'s status on Saturday, 20-Jul-2024 22:29:28 JST Khleedril Khleedril
      in reply to

      @GossiTheDog I know they are denying it, but I find it hard to believe this isn't a case of deliberate sabotage.

      In conversation Saturday, 20-Jul-2024 22:29:28 JST permalink
    • Embed this notice
      Erik Ableson (erik@mastodon.infrageeks.social)'s status on Saturday, 20-Jul-2024 23:50:39 JST Erik Ableson Erik Ableson
      in reply to

      @GossiTheDog Out of the gate qualifying question for these vendors: is your software written in a memory-safe language?

      In conversation Saturday, 20-Jul-2024 23:50:39 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 21-Jul-2024 00:35:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Microsoft estimate almost 9 million Windows devices are impacted by the CrowdStrike incident (likely from crash telemetry). https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/

      In conversation Sunday, 21-Jul-2024 00:35:46 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Helping our customers through the CrowdStrike outage - The Official Microsoft Blog
        from @microsoft
        On July 18, CrowdStrike, an independent cybersecurity company, released a software update that began impacting IT systems globally. Although this was not a Microsoft incident, given it impacts our ecosystem, we want to provide an update on the steps we’ve taken with CrowdStrike and others to remediate and support our customers.  Since this event began,...
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Sunday, 21-Jul-2024 01:59:12 JST 翠星石 翠星石
      in reply to
      @GossiTheDog Ah yes, the consequences of running windows on computers that should have been running GNU/Linux.
      In conversation Sunday, 21-Jul-2024 01:59:12 JST permalink
    • Embed this notice
      Tyrone Slothrop (slothrop@chaos.social)'s status on Sunday, 21-Jul-2024 02:41:07 JST Tyrone Slothrop Tyrone Slothrop
      in reply to

      @GossiTheDog In reality it was just 1 million devices, which each got rebooted 9 times on average 🤡

      In conversation Sunday, 21-Jul-2024 02:41:07 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 21-Jul-2024 02:41:43 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Hackers reboot announced for 2025, trailer dropped

      In conversation Sunday, 21-Jul-2024 02:41:43 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/820/043/834/466/603/original/e7cb818ec76ed9fc.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 22-Jul-2024 02:15:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Verge has a quick look at the orgs trying to recover from the Crowdstrike incident.

      If you’re wondering why it’s dropped off the radar of most press, they think it’s over as Down Detector looks okay (which, to be clear, is not good logic).

      https://www.theverge.com/2024/7/21/24202960/crowdstrike-windows-outage-it-workers-photos-videos

      In conversation Monday, 22-Jul-2024 02:15:58 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.theverge.com
        CrowdStrike outage: Photos, videos, and tales of IT workers fixing BSODs
        from Wes Davis
        There’s no simple fix for CrowdStrike’s faulty update.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 02:42:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      How much is a significant number?

      In conversation Tuesday, 23-Jul-2024 02:42:37 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/831/372/314/416/720/original/459c7d6ded3e2767.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 02:54:14 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Interesting - did anybody keep a list of tweets by CrowdStrike staff during the start of the incident? This one has been deleted. https://x.com/brody_n77/status/1814186136149037459

      In conversation Tuesday, 23-Jul-2024 02:54:14 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/831/415/280/436/358/original/3e3643aa12b124da.jpeg

      2. https://cyberplace.social/system/media_attachments/files/112/831/415/593/898/726/original/3ee2a8e624b47efe.jpeg

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 05:49:09 JST Kevin Beaumont Kevin Beaumont
      in reply to

      US House committee calls on CrowdStrike CEO to testify on global outage https://www.washingtonpost.com/technology/2024/07/22/house-committee-calls-crowdstrike-ceo-testify-global-outage/

      In conversation Tuesday, 23-Jul-2024 05:49:09 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.washingtonpost.com
        House committee calls on CrowdStrike CEO to testify on global outage
        Software security company faces prospect of congressional grilling over botched update that caused widespread havoc.
    • Embed this notice
      Wolfie (wolfie@blahaj.social)'s status on Tuesday, 23-Jul-2024 07:43:05 JST Wolfie Wolfie
      in reply to

      @GossiTheDog Well this will be absolutely jam-packed with good takes, I’m sure

      In conversation Tuesday, 23-Jul-2024 07:43:05 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 08:55:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Crowdstrike are touting auto remediation of blue screen as an opt in feature.

      However, I just tried it - it’s not very successful, most boots still blue screen of death. I think CS need to be careful on messaging about this as it sounds like they’re offering it as a silver bullet. It only works if networking kicks in and the agent updates before Windows finishes booting.

      https://www.reddit.com/r/sysadmin/comments/1e9nqyn/just_exited_a_meeting_with_crowdstrike_you_can/

      In conversation Tuesday, 23-Jul-2024 08:55:24 JST permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 18:33:10 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Delta cancelled another 20% of US flights yesterday as they struggle to recover from CrowdStrike incident https://www.bankinfosecurity.com/blogs/crowdstrike-disruption-restoration-taking-time-p-3673

      In conversation Tuesday, 23-Jul-2024 18:33:10 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/835/110/562/188/548/original/c5fa4566854a9557.jpeg
      2. Domain not in remote thumbnail source whitelist: 4a7efb2d53317100f611-1d7064c4f7b6de25658a4199efb34975.ssl.cf1.rackcdn.com
        CrowdStrike Disruption Restoration Is Taking Time
        from @BnkInfoSecurity
        Microsoft's statement that a faulty CrowdStrike update affected less than 1% of active Windows systems doesn't tell the full story, since large organizations in critical sectors make up a disproportionate part of the user base, as the outages in healthcare, transportation and banking demonstrate.
    • Embed this notice
      Stanislav Ochotnický (drizzy@cyberplace.social)'s status on Tuesday, 23-Jul-2024 18:42:11 JST Stanislav Ochotnický Stanislav Ochotnický
      in reply to

      @GossiTheDog I suppose crowdstrike could use this outage as their carbon credits. Hey look how much co2 saved it with this simple trick!

      In conversation Tuesday, 23-Jul-2024 18:42:11 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 20:08:44 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike have published a video on YouTube about how to remediate PCs: https://www.youtube.com/watch?v=Bn5eRUaMZXk

      In conversation Tuesday, 23-Jul-2024 20:08:44 JST permalink

      Attachments

      1. CrowdStrike Host Self-Remediation for Remote Users with Local Administrator Privileges
        from CrowdStrike
        This video for remote users with local administrator privileges, outlines the steps required to self-remediate a Windows laptop experiencing a blue screen of...
    • Embed this notice
      Sandrew :clubtwit: (sandrew@twit.social)'s status on Tuesday, 23-Jul-2024 20:33:41 JST Sandrew :clubtwit: Sandrew :clubtwit:
      • Infoseepage

      @Infoseepage @GossiTheDog That's only if you didn't authenticate to Wi-Fi before logon (e.g. at the logon screen), which shouldn't be the case in many corporate environments (who are the only ones using CrowdStrike), as they'd have pushed the Wi-Fi settings via group policy

      In conversation Tuesday, 23-Jul-2024 20:33:41 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 23:09:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Delta are still struggling, suspending additional services.

      In conversation Tuesday, 23-Jul-2024 23:09:24 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/836/195/937/735/334/original/e822e52b3ee0b342.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jul-2024 23:12:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Upguard have published a list of companies they say are impacted by the CrowdStrike 'Global IT Outage', based on public reporting.

      https://www.upguard.com/crowdstrike-outage

      In conversation Tuesday, 23-Jul-2024 23:12:46 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 24-Jul-2024 01:42:02 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody wonders what the file that took down 8.5 million Windows systems looks like.. it was 41kb in size.

      In conversation Wednesday, 24-Jul-2024 01:42:02 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/836/795/152/727/714/original/27334a49deaceb77.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 24-Jul-2024 01:58:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The US Department of Transport has opened an investigation into Delta over the disruption related to CrowdStrike incident.

      Good luck to the CrowdStrike account manager for Delta.

      In conversation Wednesday, 24-Jul-2024 01:58:24 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/836/857/412/935/827/original/bae527f62592f584.png
    • Embed this notice
      Adam Collins (m104@mastodon.social)'s status on Wednesday, 24-Jul-2024 01:59:50 JST Adam Collins Adam Collins
      in reply to

      @GossiTheDog Is there sort of signed signature or checksum or does the CrowdStrike agent just say "YOLO whatever we downloaded let's just start processing it" ?

      In conversation Wednesday, 24-Jul-2024 01:59:50 JST permalink
    • Embed this notice
      Piggo :verified_horse: (piggo@piggo.space)'s status on Wednesday, 24-Jul-2024 02:02:26 JST Piggo :verified_horse: Piggo :verified_horse:
      in reply to
      @GossiTheDog do u think this the fallout will kill the company? it's like the biggest fuckup you can possibly make
      In conversation Wednesday, 24-Jul-2024 02:02:26 JST permalink
    • Embed this notice
      codeandroid 🇺🇦 (codeandroid@mastodon.social)'s status on Wednesday, 24-Jul-2024 02:17:37 JST codeandroid 🇺🇦 codeandroid 🇺🇦
      • Piggo :verified_horse:

      @GossiTheDog @piggo Is there a good answer to the question: Which vendor is proven to have better processes (and less bad kernel drivers)?

      In conversation Wednesday, 24-Jul-2024 02:17:37 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 24-Jul-2024 16:49:33 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The initial Post Incident Review is out from CrowdStrike. It’s good and really honest.

      There’s some wordsmithing (eg channel updates aren’t code - their parameters control code).

      The key take away - channel updates are currently deployed globally, instantly. They plan to change this at a later date to operate in waves. This is smart (and what Microsoft do for similar EPP updates).

      https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/

      In conversation Wednesday, 24-Jul-2024 16:49:33 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.crowdstrike.com
        Falcon Content Update Remediation and Guidance Hub | CrowdStrike
        Access consolidated remediation and guidance resources for the CrowdStrike Falcon content update affecting Windows hosts.

      2. https://cyberplace.social/system/media_attachments/files/112/840/365/510/105/866/original/8463c1f1854f557e.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 24-Jul-2024 17:27:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      By ‘this is smart’ I mean ‘this is smart… now’. Obviously they shouldn’t have been globally, simultaneously deploying kernel driver parameter changes across all customers: it was waiting to go wrong.

      They still are btw, as it will take a while to engineer the correct way of doing it.

      In conversation Wednesday, 24-Jul-2024 17:27:07 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 02:34:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      On insurance and CrowdStrike, Parametrix claim amongst just the Fortune 500 companies, they are facing $5.4bn in losses, of which around 10% will be covered by insurance.
      https://www.theguardian.com/technology/article/2024/jul/24/crowdstrike-outage-companies-cost

      In conversation Thursday, 25-Jul-2024 02:34:04 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: i.guim.co.uk
        CrowdStrike global outage to cost US Fortune 500 companies $5.4bn
        from https://www.theguardian.com/profile/nick-robins-early
        Banking and healthcare firms, major airlines expected to suffer most losses, according to insurer Parametrix
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 02:52:11 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • qwertyoruiopz

      CrowdStrike have won this year's Pwnie Award for Epic Fail, which will please @qwertyoruiop.

      In conversation Thursday, 25-Jul-2024 02:52:11 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/842/730/994/459/960/original/6b09d3ccf8e8cfba.png

      2. https://cyberplace.social/system/media_attachments/files/112/842/732/062/669/695/original/0836a4edbdd833f7.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.