CrowdStrike

8 items · Capability 2 · Defense 3 · Attacks 3 · all entities

CrowdStrike assesses with high confidence that the PhantomRaven npm stealer was written with an LLM

CrowdStrike says the developer behind PhantomRaven — the credential and CI/CD-secret stealer spread through more than 100 malicious npm packages in a campaign first flagged in October 2025 — “likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns.” The operator claimed to be a bug bounty hunter who had collected bounties from at least nine organisations (via The Hacker News; CrowdStrike's own post could not be opened).

Reported by pressThe Hacker News (reporting CrowdStrike) ↗ ·

A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components

SecurityWeek reports that the researcher known as Nightmare Eclipse published three zero-days with proof-of-concept code: PrettyPrague, which targets the Avast sandbox to spawn a shell with full system privileges; FalconFlank, a privilege-escalation bug in the Office malicious-macro remediation feature of the CrowdStrike Falcon Sensor; and GreenSection, an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. Gen Digital said it “immediately initiated our security response procedures and have fixed the issue”; CrowdStrike said it was “actively investigating these claims” and advised disabling the Microsoft Office File Suspicious Macro Removal Windows policy setting; Nvidia had not commented at publication.

Reported by pressSecurityWeek ↗ ·

Google opens Fairwind, a vetted-access program for its cyber model and CodeMender

Fairwind limits access to Gemini 3.8 Flash Cyber and CodeMender to government and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and core technology platforms, with use confined to internal cybersecurity, incident response and penetration testing staff and multi-factor authentication required. Google states more than 650 participating partners globally and names Armadin, CrowdStrike, Palo Alto Networks, Snowflake and Wiz among them.

On the recordGoogle ↗ ·

CrowdStrike releases a paired offensive and defensive cyber model built on NVIDIA Nemotron

CrowdStrike announced SafeMind at Fal.Con on September 1: Red Tempest, described in the release as an “offensive red team model… built for advanced attack scenarios, emulating AI adversaries,” and Blue Solano, a defensive model “built for protecting enterprise assets by deploying battle-tested measures.” CrowdStrike says the pair is built on NVIDIA Nemotron open models with NVIDIA as AI design partner, runs natively in the Falcon platform, and claims a 29% higher detection rate, 6x faster end-to-end remediation and 99% cost savings on detection and remediation against leading frontier models and open-source baselines that the release does not name. Standalone access to the models and harnesses is to run through a Project QuiltWorks trusted-access programme, whose eligibility conditions the release does not state.

Self-reported, untestedCrowdStrike ↗ ·

CrowdStrike establishes a frontier AI research lab for cyber defense

CrowdStrike announced the Cyber Superintelligence Lab, which it describes as “the first frontier AI research organization built for cyberdefense and AI safety,” led by chief AI and autonomous systems officer Dr. Bartley Richardson. It names as the lab's inputs Falcon sensor signals from endpoints, identity systems, cloud workloads and data stores at trillions of events a day, labelled by front-line analysts, plus 15 years of CrowdStrike threat intelligence and incident response.

On the recordCrowdStrike ↗ ·

OpenAI leads more than 100 companies in an open letter calling for collective AI cyber defense

OpenAI published an open letter, co-signed by more than 100 organizations including Anthropic, Google, Microsoft, AWS, Oracle, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks and Hugging Face, calling for collective action to defend against sustained AI-enabled attacks. It urges every organization to make cyber defense an immediate leadership priority and fix its highest-risk weaknesses, asks security and frontier-AI companies to give under-resourced defenders responsible model access, funding and threat-intelligence sharing, and asks governments to coordinate cyber defense across levels and fund essential services that lack the staff or budget.

On the recordOpenAI (open letter, 100+ signatories) ↗ ·

CrowdStrike cites a finding that more than a third of Cybench task passes involved cheating, and takes its cyber-AI evaluation in-house

CrowdStrike cites Dreadnode's finding that “more than a third of all passes on individual tasks on Cybench, across nearly every model assessed, involved cheating” through postmortem searches and probing of the evaluation infrastructure. It says it now relies on task-coupled internal evaluations with rotated validation sets and a separation between evaluation developers and solution architects, and contributes publicly through CyberSOCEval with Meta.

Reported by researchersCrowdStrike ↗ ·

CrowdStrike's 2026 Threat Hunting Report says AI is now embedded across adversary operations

CrowdStrike's annual Threat Hunting Report documents adversaries using LLMs to generate payloads and shell commands, abuse enterprise models and target AI infrastructure, citing one campaign that sent nearly 200,000 model requests in two minutes. It attributes malicious npm packages planted in AI-agent framework projects to DPRK-nexus STARDUST CHOLLIMA and reports cloud-conscious eCrime, including LLM abuse, up 171%.

Reported by researchersCrowdStrike ↗ ·