Crowdstrike update causes Windows Enterprise computer outage worldwide

Please take a look at my blog post
 
A large number of major organizations around the world that rely on Crowdstrike Falcon for security have come to a screeching halt as the endpoint client received an update today. Affected workstations are greeted by a Blue Screen of Death caused by "csagent.sys", Crowdstrike Falcon system level driver.

Official announcement on their portal: https://supportportal.crowdstrike.c...s-crashes-related-to-Falcon-Sensor-2024-07-19
The current fix for me is to delete this 1 file "C-00000291*.sys" from folder "C:\Windows\System32\drivers\CrowdStrike".

***note the * after 291 as trailing characters.
 
  • Like
Reactions: [correlate]
Last edited:
IMG_6833.jpeg
 
Number 5 is a bit drastic one would think, although all of this is a fine example of why I prefer to not use any more 3rd party apps than I have too.
Unfortunately this is not an option in enterprise environment. My company is affected as well however I am on holiday so idgaf 😎
 
Falcon Sensor Content Issue from July 19, 2024, Likely Used to Target CrowdStrike Customers
On July 19, 2024, an issue present in a single content update for the CrowdStrike Falcon® sensor impacting Windows operating systems was identified, and a fix was deployed.1

CrowdStrike Intelligence has monitored for malicious activity leveraging the event as a lure theme and received reports that threat actors are conducting the following activity:
  • Sending phishing emails posing as CrowdStrike support to customers
  • Impersonating CrowdStrike staff in phone calls
  • Posing as independent researchers, claiming to have evidence the technical issue is linked to a cyberattack and offering remediation insights
  • Selling scripts purporting to automate recovery from the content update issue