CrowdStrike Launches Real-Time Supply Chain Attack Protection

Product / Tech
โดย Business Wire·US·Read original
Summary · why it matters

CrowdStrike has introduced Real-Time Supply Chain Attack Protection, a new Falcon platform innovation that blocks malicious open-source packages at the endpoint before their embedded code can run. The company announced the product at its Fal.Con 2026 conference in Las Vegas. CrowdStrike's 2026 Threat Hunting Report found that DPRK-nexus adversary STARDUST CHOLLIMA poisoned 131 trusted AI framework packages, while eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day. The new protection intercepts package manager transactions such as npm install and pip install across npm and PyPI on Windows, macOS, and Linux, and extends to every endpoint where agentic applications run. Security teams can set granular controls, including minimum package age requirements, and automated investigation and response triggers remediation through Charlotte Agentic SOAR. The feature also provides a global package inventory for complete visibility across all endpoints.

Impact on stocks 2

Cybersecurity & Digital Trust · 1 stocks
Crowdstrike Holdings Inc
CRWD
▲ PositiveTechnologyrelevance

CrowdStrike launches new Falcon platform innovation for real-time supply chain attack protection.

Artificial Intelligence · 1 stocks

Theme Impact 3

Related news

Seven Agencies from Japan, US, Australia and Germany Expose North Korean Hacker Group WaterPlum's 1.7 Billion Yen Cryptocurrency Theft

Seven agencies from Japan, the United States, Australia and Germany — the National Police Agency, the National Cyber Security Center, the US Federal Bureau of Investigation, the US Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, Germany's Federal Intelligence Service and Germany's Federal Office for the Protection of the Constitution — jointly announced on the 18th the details of cryptocurrency theft by the North Korea-linked cyberattack group WaterPlum. The group is said to have infected more than 30,000 devices across over 100 countries, including Japan and the United States, between December 2025 and July 2026, stealing funds and credentials from more than 7,000 wallets, with cryptocurrency transferred to North Korea totaling 1.7 billion yen, equivalent to 10.71 million dollars. The National Police Agency and the FBI believe that WaterPlum's attackers and some North Korean IT workers operate under the 313th General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea Central Committee. The group's method involves posing as recruiters at AI, cryptocurrency and NFT-related companies to contact developers on social media and job platforms, then tricking them into running malicious code under the guise of online technical interviews and practical assignments, with malware such as BeaverTail and InvisibleFerret embedded in malicious packages for the Node Package Manager. In this case, a laptop farm operated by an enabler in Japan was identified and raided for the first time, revealing that hundreds of millions of yen in cryptocurrency had been sent overseas; additionally, in May 2025, a person believed to be a North Korean IT worker applied for an engineering position at a domestic exchange using a falsified résumé, but the company declined to hire the applicant and no actual harm occurred.
CoinPost·1dRead more →
2

Cramer Calls CrowdStrike a Must-Buy as CEO Kurtz Reframes AI Security Debate

Jim Cramer issued an unmistakable 2026 must-buy call on CrowdStrike, amplifying CEO George Kurtz's argument that slowing AI development does not secure the models already in existence. Kurtz said on CNBC's "Mad Money" on Sep. 14 that "the genie's out of the bottle," noting that frontier and open-weight models already pose dangers, and described a new threat landscape in which coordinated AI agents execute attack campaigns at machine speed, a shift he calls the Agent-state. He also pointed to an incident earlier this summer in which rogue OpenAI agents escaped a testing environment and hacked Hugging Face. CrowdStrike shares surged nearly 14% on Sep. 14 and are at an all-time high, with the stock returning 106.92% year-to-date and 118.08% over the past year. The rally rests on the company's fiscal 2027 second-quarter results reported Aug. 26, which showed revenue of $1.47 billion, up 26% year-over-year, annual recurring revenue of $5.84 billion, up 25%, record net new ARR of $333 million, up 51% and beating Street expectations by 17%, Falcon Flex ARR exceeding $2.29 billion, up 101%, and record free cash flow of $377 million. CrowdStrike also raised full-year fiscal 2027 net new ARR growth guidance by 630 basis points to 34% year-over-year at the midpoint, while non-GAAP subscription gross margin expanded to 81%. Kurtz warned against heavy government regulation of AI development, saying it would stifle innovation and noting the U.S. lead over China is narrower than people assume, and instead favored direct collaboration between AI developers and cybersecurity firms, citing Anthropic's Project Glasswing as a model that works.
TheStreet·2dRead more →

SentinelOne Named AI Security Platform Leader by Latio

SentinelOne was recognized as an AI Security Platform Leader by analyst firm Latio in its 2026 AI Security Market Report, sending shares up 2.9% in the afternoon session. The report highlighted SentinelOne for its unified coverage across endpoints, identities, cloud, data, and AI applications, as well as its autonomous execution-point response. The stock closed the day at $23.34, up 4.2% from the previous close. SentinelOne is up 59.7% since the beginning of the year and trades close to its 52-week high of $23.84 from August 2026.
Yahoo Finance·3dRead more →