Skip to content

Defense Digests

D3 Alert: Global IT Outage – What to know, What to do 

d3

Table of content

We are aware of public reports of a global IT outage caused by a faulty update to many user’s IT security systems. We have assessed the extent of the outage and have determined that the update appears to be related to Crowdstrike – who is reporting that many of their users are experiencing a Blue Screen for their Windows PCs and Servers.  

Crowdstrike has stated customers were impacted due to “a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack.” 

What Should I Know:  

This outage is global and is not related to Dataprise or Dataprise services. The issue is related to a security system that Dataprise uses for protection of customer environments. Upon notification of the issue, Dataprise technicians began blocking the update to customer environments.  

What Should Customers Do:  

If you experience any issue related to a Blue Screen, please call the service desk who can help with initiating the recovery processes.   

What is Dataprise Doing:  

Upon notification of the issue, Dataprise has taken mitigating actions to block the update from being deployed to customers.  At this time we believe that if you have not been affected by the issue you are unlikely to experience it.   

Detailed Technical Details:  

Full knowledge Base Article is located here: (Must have a Crowdstrike ID to access)  

Tech Alert | Windows crashes related to Falcon Sensor | 2024-07-19 (crowdstrike.com) 

Published Date: Jul 19, 2024 

Summary 

CrowdStrike is aware of reports of crashes on Windows hosts related to the Falcon Sensor. 

Details 

Symptoms include hosts experiencing a bugcheck\blue screen error related to the Falcon Sensor. 

This issue is not impacting Mac- or Linux-based hosts 

Channel file “C-00000291*.sys” with timestamp of 0527 UTC or later is the reverted (good) version. 

Current Action 

CrowdStrike Engineering has identified a content deployment related to this issue and reverted those changes. 

If hosts are still crashing and unable to stay online to receive the Channel File Changes, the following steps can be used to workaround this issue: 

Workaround Steps: 

Reboot the host to give it an opportunity to download the reverted channel file.  If the host crashes again, then: 

Boot Windows into Safe Mode or the Windows Recovery Environment 

Navigate to the C:\Windows\System32\drivers\CrowdStrike directory 

Locate the file matching “C-00000291*.sys”, and delete it.  

Boot the host normally. 

Note:  Bitlocker-encrypted hosts may require a recovery key.  

Latest Updates 

2024-07-19 05:30 AM UTC | Tech Alert Published. 

2024-07-19 06:30 AM UTC | Updated and added workaround details. 

2024-07-19 08:08 AM UTC | Updated 

Recent Tweets

INSIGHTS

Learn about the latest threats and vulnerabilities with our D3 alerts.

Subscribe to get real-time notifications when a new Dataprise Defense Digest is published.