• On July 19, CrowdStrike released a sensor configuration update to Windows systems that triggered a logic error resulting in system crashes and blue screens. The issue was caused by an updated Channel File 291 (a config file) that controls how Falcon evaluates named pipe execution. CrowdStrike has corrected the error and updated the file, but billions of systems are still affected.

  • CrowdStrike caused a global outage by pushing a faulty configuration update to its Falcon product, resulting in the crash of 8.5 million Windows machines. The update aimed to enhance threat detection but contained a logic error that caused the CSAgent.sys process to crash the operating system. The recovery process was slow and manual, requiring physical access to each impacted machine. While CrowdStrike is primarily responsible, Microsoft's inability to restrict third-party software from running at kernel level due to a 2009 agreement with the European Commission also worsened the situation.