<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: CrowdStrike Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving CrowdStrike.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Malware is targeting AI tools in software development environments</title><link>https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike</link><guid isPermaLink="false">cst-3038</guid><description>Sandworm_Mode, a self-propagating worm discovered in February, targets AI coding assistants and software development environments to steal credentials, API keys, and secrets from CI/CD pipelines and major language model providers. The malware blends its activity with legitimate development traffic, uses multi-day delays to evade detection, and destroys compromised environments if unable to spread. CrowdStrike has monitored the threat for four months but has not determined its origin or ultimate intent, though it appears designed for persistent access and may represent a broader trend of supply-chain attacks against AI development toolchains.</description><pubDate>Wed, 22 Jul 2026 17:24:46 GMT</pubDate></item><item><title>Why Modern SOCs Need Multi-Layered Detections</title><link>https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html</link><guid isPermaLink="false">cst-3000</guid><description>The article argues that modern security operations centers require multi-layered detection approaches because traditional endpoint and malware-based defenses no longer catch most attacks. According to the CrowdStrike Global Threat Report, approximately 79% of attacks are malware-free, with threat actors increasingly relying on techniques that evade conventional security tools.</description><pubDate>Wed, 22 Jul 2026 11:25:35 GMT</pubDate></item><item><title>How a Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure flagged 24 hours before it launched</title><link>https://silentpush.com/blog/scattered-lapsus-shinyhunters-attack</link><guid isPermaLink="false">cst-2854</guid><description>A Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure that Silent Push had flagged 24 hours before the campaign launched. The threat actor group conducted a social engineering attack directing an employee to a lookalike domain, but the organization used Silent Push to enumerate the full adversary infrastructure and block all related domains within minutes, stopping both the initial and a subsequent attack attempt. The case demonstrates the value of tracking adversary infrastructure during the staging phase rather than relying solely on post-incident indicators.</description><pubDate>Mon, 20 Jul 2026 15:13:33 GMT</pubDate></item><item><title>Leading members of Scattered Spider sentenced in UK to 66 months in jail</title><link>https://cyberscoop.com/scattered-spider-leaders-sentenced-united-kingdom</link><guid isPermaLink="false">cst-2771</guid><description>Two young men, Thalha Jubair and Owen Flowers, were sentenced to 66 months in jail by UK courts for their roles in a 2024 cyberattack on Transport for London. Both were leading members of Scattered Spider, a cybercriminal group responsible for at least 120 attacks including extortion targeting 47 U.S. organizations, the federal court system, and healthcare companies, with traced cryptocurrency payments exceeding $89.5 million. UK authorities claimed the arrests effectively halted the group's operations, though the FBI noted other cybercriminals continue to exploit the Scattered Spider brand in ongoing attacks.</description><pubDate>Fri, 17 Jul 2026 14:12:59 GMT</pubDate></item><item><title>Why Halcyon? A SOC Operator's Answer.</title><link>https://halcyon.ai/blog/why-halcyon-soc-operators-answer</link><guid isPermaLink="false">cst-1995</guid><description>An article discusses the architectural differences between Halcyon and competing security platforms like CrowdStrike, SentinelOne, and Microsoft Defender from the perspective of a field CISO evaluating endpoint protection options during ransomware incidents.</description><pubDate>Wed, 24 Jun 2026 00:04:04 GMT</pubDate></item><item><title>Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more.</title><link>https://recordedfuture.com/blog/recorded-future-named-a-leader</link><guid isPermaLink="false">cst-1963</guid><description>Recorded Future has been recognized as a Leader in Gartner's inaugural Magic Quadrant for Cyberthreat Intelligence Technologies, evaluated among 17 vendors in the market. The company is introducing a simplified product structure with four new solutions focused on cyber operations, digital risk protection, third-party risk, and payment fraud detection, built on a unified intelligence platform that integrates with tools like CrowdStrike Falcon and Google SecOps.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?</title><link>https://sentinelone.com/labs/labscon25-replay-are-your-chinese-cameras-spying-for-you-or-on-you</link><guid isPermaLink="false">cst-609</guid><description>Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.</description><pubDate>Wed, 22 Apr 2026 22:00:15 GMT</pubDate></item><item><title>GreyNoise Intelligence Is Available Across the CrowdStrike Falcon Platform</title><link>https://greynoise.io/blog/greynoise-intelligence-available-across-crowdstrike-falcon-platform</link><guid isPermaLink="false">cst-1856</guid><description>GreyNoise Intelligence has been integrated into the CrowdStrike Falcon platform, enabling security teams to access internet-wide scanning context within SIEM queries, SOAR workflows, and AI-driven triage systems. This integration combines GreyNoise's threat intelligence capabilities with CrowdStrike's endpoint detection and response infrastructure.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title>CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04</title><link>https://crowdstrike.com/en-us/blog/crowdstrike-falcon-platform-helps-meet-us-goverment-mandates-cisa-bod-26-04</link><guid isPermaLink="false">cst-3067</guid><description>CrowdStrike announced that its Falcon Platform aligns with requirements set by the Cybersecurity and Infrastructure Security Agency (CISA) through Board Directive (BOD) 26-04. The announcement indicates the platform's capabilities support compliance with federal cybersecurity mandates.</description><pubDate>Sun, 26 Jul 2026 22:32:52 GMT</pubDate></item><item><title>AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity</title><link>https://crowdstrike.com/en-us/blog/aidr-how-crowdstrike-is-defining-next-era-of-cybersecurity</link><guid isPermaLink="false">cst-2631</guid><description>The article appears to be a stub or promotional piece with no substantive content, event details, or technical findings to convey about AIDR or CrowdStrike's approach.</description><pubDate>Sun, 26 Jul 2026 22:32:52 GMT</pubDate></item><item><title>CrowdStrike Uncovers New Prompt Injection Techniques</title><link>https://crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques</link><guid isPermaLink="false">cst-2099</guid><description>CrowdStrike has identified new prompt injection techniques that threat actors are using to manipulate AI systems. These methods represent an evolving attack vector against large language models and other AI applications.</description><pubDate>Sun, 26 Jul 2026 22:32:52 GMT</pubDate></item><item><title>CrowdStrike Announces Continuous Identity for AI Agents</title><link>https://crowdstrike.com/en-us/blog/crowdstrike-announces-continuous-identity-for-ai-agents</link><guid isPermaLink="false">cst-657</guid><description>CrowdStrike announced a new product offering called Continuous Identity for AI Agents, which aims to address identity and access management challenges specific to artificial intelligence agents operating in enterprise environments.</description><pubDate>Sun, 26 Jul 2026 22:32:52 GMT</pubDate></item><item><title>94% of Organizations Report Cloud Breaches: CrowdStrike State of CDR Survey</title><link>https://crowdstrike.com/en-us/blog/crowdstrike-state-of-cdr-survey-key-takeaways</link><guid isPermaLink="false">cst-652</guid><description>A CrowdStrike survey reports that 94% of organizations experienced cloud breaches, highlighting widespread exposure in cloud environments. The findings underscore the prevalence of cloud security incidents across enterprises. Cloud detection and response capabilities are increasingly critical as attackers target cloud infrastructure.</description><pubDate>Sun, 26 Jul 2026 22:32:52 GMT</pubDate></item></channel></rss>