Windows making changes to stop another CrowdStrike incident | Tech Reader

Date:

Share:


Microsoft

Microsoft is looking to create a new platform inside the Windows OS that is tailored for antivirus monitoring. This platform would prevent security products from accessing the kernel, as Microsoft mentioned in an Experience Blog post. Microsoft is making this move to avoid a repeat of the infamous CrowdStrike incident in July.

The new platform idea was mentioned during a summit held on September 10, 2024, at the tech giant’s Redmond, Washington, headquarters. Microsoft mentioned the summit’s purpose by saying: “This forum brought together a diverse group of endpoint security vendors and government officials from the U.S. and Europe to discuss strategies for improving resiliency and protecting our mutual customers’ critical infrastructure.”

Microsoft also clarified that this wasn’t a decision-making meeting, but wanted to share the consensus points and key themes. The software giant also shared the requirements and challenges it faced in creating the new platform. For example, Some of the areas discussed included:

  • Performance needs and challenges outside of kernel mode
  • Anti-tampering protection for security products
  • Security sensor requirements
  • Development and collaboration principles between Microsoft and the ecosystem
  • Secure-by-design goals for future platform

Microsoft is not confirming that it will make the kernel inaccessible, but is laying the groundwork for designing the security platform to transfer CrowdStrike and others out of the kernel. This is a long-term project, but it will continue working to achieve enhanced reliability without compromising security.

At the summit, antivirus provider ESET also said, ” It remains imperative that kernel access remains an option for use by cybersecurity products to allow continued innovation and the ability to detect and block future cyberthreats. We look forward to the continued collaboration on this important initiative.”

They also gave tips that customers can use to stay safe, such as backing up data securely and having a business continuity plan and a major incident response plan. The disastrous CrowdStrike failure crashed 8.5 million Windows PCs and servers, affecting various industries, but airlines were hit the hardest.








Source link

━ more like this

The FBI confirms it’s buying Americans’ location data

During a Senate hearing, FBI Director Kash Patel confirmed that his agency has bought information that could be used to track individuals' movement...

A Meta agentic AI sparked a security incident by acting without permission

The Information reported that an AI agent within Meta took unauthorized action that led to an employee creating a security breach at the...

Microsoft will no longer auto-install M365 Copilot app on Windows PCs

Microsoft has stopped automatically installing the Microsoft 365 Copilot app on Windows PCs with M365 apps, after initially planning to roll it out...

A new iPhone hacking tool puts anyone still on iOS 18 at risk

Google and cybersecurity companies Lookout and iVerify have detailed a new hacking technique that potentially puts a significant portion of iPhone users in...

Senator Blackburn introduces the first draft of a federal AI bill

The White House has been promising a set of national rules to guide artificial intelligence since late last year, and today Sen. Marsha...
spot_img