Microsoft Windows Outage Caused by Sensor Update, Systems Recovering

Apps & Games / Desktop / Windows / Microsoft Windows Outage Caused by Sensor Update, Systems Recovering
20 Jul 2024

A sensor configuration update for Microsoft Windows systems that went wrong was the cause of what is now being identified as possibly the largest IT outage in history. The IT outage on July 19 started when the CrowdStrike software update triggered a logic error. This led to a system crash and caused the ‘blue screen of death’ that many saw on their affected devices. The logic error has since been corrected and systems are returning to normal around the world, said CrowdStrike in a release covering the technical details of the outage. Those affected were largely customers running the Falcon sensor for Windows version 7.11 and above, who were online during certain intervals on July 19.

Details of the Outage

CrowdStrike said that sensor configuration updates were an “ongoing part of the protection mechanisms of the Falcon platform”—its endpoint protection service. “The update that occurred at 04:09 UTC was designed to target newly observed, malicious named pipes being used by common C2 frameworks in cyberattacks. The configuration update triggered a logic error that resulted in an operating system crash,” noted CrowdStrike. The cause of the incident was not a cyberattack, the company stressed. Microsoft earlier said that “Virtual Machines running Windows Client and Windows Server, running the CrowdStrike Falcon agent, may encounter a bug check”. The approximate time of impact could have been as early as 9.39 a.m. IST on July 19, when the CrowdStrike update started rolling out.

Steps for Affected Users

To get the latest information about fixing the error and coming back online, users can visit the CrowdStrike website’s blog or support portal. They can also reach out to the company directly.

Related Stories

  • Meta content moderation vendors hit by global cyber outage
  • Major internet outages in recent times

Related Topics

  • technology (general)
  • internet

How to disable crowdstrike falcon sensor temporarily mac?

To temporarily disable CrowdStrike Falcon Sensor on a Mac, follow these steps: 1. Open Terminal. 2. Enter the command `sudo /Applications/Falcon.app/Contents/Resources/falconctl disable`. 3. You will be prompted to enter your admin password. Note that this action might be restricted based on your organization's policy, and you may need to contact your IT administrator for appropriate permissions.

How to disable crowdstrike falcon sensor temporarily?

To temporarily disable CrowdStrike Falcon Sensor, you can use Terminal (Mac) or Command Prompt (Windows): On Mac: 1. Open Terminal. 2. Run `sudo /Applications/Falcon.app/Contents/Resources/falconctl disable`. On Windows: 1. Open Command Prompt as Administrator. 2. Run `sc config csagent start= disabled` followed by `sc stop csagent`. Note that administrative permissions may be required, and you should check with your IT administrator if you do not have the necessary access.
Update: 20 Jul 2024