Geek-Guy.com

Tag: CrowdStrike

CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday.  The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed to…

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions. “Since at least early 2025, GlassWorm operators have systematically targeted software developers, a

CrowdStrike Disrupts Glassworm Supply Chain Botnet 

CrowdStrike announced the coordinated takedown of the Glassworm botnet, a large-scale operation that targeted software developers through compromised open-source packages, malicious VSCode extensions, and poisoned GitHub repositories.  The operation, conducted alongside Google and the Shadowserver Foundation, disrupted the botnet’s infrastructure and severed communication between the operators and infected systems. “In collaboration with Google and the…

CrowdStrike Builds Project QuiltWorks for AI-era Bugs

CrowdStrike has launched Project QuiltWorks, a partner-led coalition aimed at helping enterprises respond faster to vulnerabilities uncovered by frontier AI models. The initiative brings together Accenture, EY, IBM Cybersecurity Services, Kroll, and OpenAI with CrowdStrike’s Falcon platform and partner network. The company said the goal is to help organizations identify, prioritize, and remediate AI-discovered vulnerabilities…

Critical bug in CrowdStrike LogScale let attackers access files

CrowdStrike fixed CVE-2026-40050 in LogScale self-hosted, a critical flaw allowing unauthenticated file access via path traversal. CrowdStrike recently disclosed a critical vulnerability, tracked as CVE-2026-40050, affecting its LogScale self-hosted product. The flaw enables unauthenticated path traversal, which could allow a remote attacker to read arbitrary files from the server filesystem. “CrowdStrike has released security updates…

Commvault Intros Bi-Directional Integration with CrowdStrike

Commvault, a unified resilience platform provider, has announced an expanded integration with CrowdStrike that delivers bi-directional visibility between Commvault Cloud and CrowdStrike Falcon Next-Gen SIEM.  The collaboration is designed to help security and IT teams verify backup integrity, enabling faster, safer, and better-informed recovery decisions.  Making informed, trusted recovery decisions According to Commvault, the integration…