Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      MultiChoice may unbundle SuperSport from DStv

      12 June 2025

      MVNO boom is reshaping South Africa’s mobile market

      12 June 2025

      South African law is failing gig-economy workers

      12 June 2025

      MultiChoice’s TV empire shrinks – but its ‘side hustles’ are holding strong

      12 June 2025

      MultiChoice is bleeding subscribers

      11 June 2025
    • World

      Qualcomm shows off new chip for AI smart glasses

      11 June 2025

      Trump tariffs to dim 2025 smartphone shipments

      4 June 2025

      Shrimp Jesus and the AI ad invasion

      4 June 2025

      Apple slams EU rules as ‘flawed and costly’ in major legal pushback

      2 June 2025

      Mark Zuckerberg has finally found a use for his metaverse

      30 May 2025
    • In-depth

      Grok promised bias-free chat. Then came the edits

      2 June 2025

      Digital fortress: We go inside JB5, Teraco’s giant new AI-ready data centre

      30 May 2025

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025

      South Africa unveils big state digital reform programme

      12 May 2025

      Is this the end of Google Search as we know it?

      12 May 2025
    • TCS

      TechCentral Nexus S0E1: Starlink, BEE and a new leader at Vodacom

      8 June 2025

      TCS+ | The future of mobile money, with MTN’s Kagiso Mothibi

      6 June 2025

      TCS+ | AI is more than hype: Workday execs unpack real human impact

      4 June 2025

      TCS | Sentiv, and the story behind the buyout of Altron Nexus

      3 June 2025

      TCS | Signal restored: Unpacking the Blue Label and Cell C turnaround

      28 May 2025
    • Opinion

      Beyond the box: why IT distribution depends on real partnerships

      2 June 2025

      South Africa’s next crisis? Being offline in an AI-driven world

      2 June 2025

      Digital giants boost South African news media – and get blamed for it

      29 May 2025

      Solar panic? The truth about SSEG, fines and municipal rules

      14 April 2025

      Data protection must be crypto industry’s top priority

      9 April 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » IT services » Computer bricked by CrowdStrike Falcon? What happened – and how to fix it

    Computer bricked by CrowdStrike Falcon? What happened – and how to fix it

    Friday's IT chaos, which disrupted businesses worldwide, has been linked to a piece of software called CrowdStrike Falcon.
    By The Conversation19 July 2024
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Computer bricked by CrowdStrike Falcon? What happened - and how to fix itA massive IT outage is affecting computer systems worldwide. From South Africa to Australia, reports indicate that computers at banks, media organisations, hospitals, transport services, shop checkouts, airports and more have all been impacted.

    The outage is unprecedented in its scale and severity. The technical term for what has happened to the affected computers is that they have been “bricked”. This word refers to those computers being rendered so useless by this outage that – at least for now – they may as well be bricks.

    Read: Global outage grounds flights, hits media, banks, telcos

    The widespread outage has been linked to a piece of software called CrowdStrike Falcon. What is it, and why has it caused such widespread disruption?

    What is CrowdStrike Falcon?

    CrowdStrike is a US cybersecurity company with a major global share in the tech market. Falcon is one of its software products that organisations install on their computers to keep them safe from cyberattacks and malware.

    Falcon is what is known as “endpoint detection and response” (EDR) software. Its job is to monitor what is happening on the computers on which it is installed, looking for signs of nefarious activity (such as malware). When it detects something fishy, it helps to lock down the threat.

    This means Falcon is what we call privileged software. To detect signs of attack, Falcon has to monitor computers in a lot of detail, so it has access to a lot of the internal systems. This includes what communications computers are sending over the internet as well as what programs are running, what files are being opened, and much more.

    Read: Capitec restores services amid global outages

    In this sense, Falcon is a bit like traditional antivirus software, but on steroids.

    More than that, however, it also needs to be able to lock down threats. For example, if it detects that a computer it is monitoring is communicating with a potential hacker, Falcon needs to be able to shut down that communication. This means Falcon is tightly integrated with the core software of the computers it runs on – Microsoft Windows.

    Why did Falcon cause this problem?

    This privilege and tight integration makes Falcon powerful. But it also means that when Falcon malfunctions, it can cause serious problems. Today’s outage is a worst-case scenario.

    What we currently know is that an update to Falcon caused it to malfunction in a way that caused Windows 10 computers to crash and then fail to reboot, leading to the dreaded “blue screen of death” (BSOD).

    This is the affectionate term used to refer to the screen that is displayed when Windows computers crash and need to be rebooted – only, in this case, the Falcon problem means the computers cannot reboot without encountering the BSOD again.

    Why is Falcon so widely used?

    CrowdStrike is the market leader in EDR solutions. This means its products – such as Falcon – are common and likely the pick of the bunch for organisations conscious of their cybersecurity.

    As today’s outage has shown, this includes hospitals, media companies, universities, major supermarkets and many more. The full scale of the impact is yet to be determined, but it’s certainly global.

    Why aren’t home PCs affected?

    While CrowdStrike’s products are widely deployed in major organisations that need to protect themselves from cyberattacks, they are much less commonly used on home PCs.

    This is because CrowdStrike’s products are tailored for large organisations in which CrowdStrike’s tools help them monitor their networks for signs of attack, and provide them with the information they need to respond to intrusions in a timely way.

    For home users, built-in antivirus sofware or security products offered by companies such as Norton and McAfee are much more popular.

    How long will this take to fix?

    At this stage, CrowdStrike has provided manual instructions for how people can fix the problem on individual affected computers.

    However, at the time of writing there does not yet appear to be an automatic fix for the problem. IT teams at some organisations may be able to fix this problem quickly by simply wiping the affected computers and restoring them from backups or similar.

    Some IT teams may also be able to “roll back” (revert to an earlier version) the affected Falcon version on their organisation’s computers. It’s also possible some IT teams will have to manually fix the problem on their organisation’s computers, one at a time.

    Multiple subsea cable breaks causing internet chaos in South AfricaWe should expect that in many organisations it may take a while before the problem can be resolved entirely.

    What is ironic about this incident is that security professionals have been encouraging organisations to deploy advanced security technology such as EDR for years. Yet that same technology has now resulted in a major outage the likes of which we haven’t seen in years.

    For companies like CrowdStrike that sell highly privileged security software, this is a timely reminder to be incredibly careful when deploying automatic updates to their products.The Conversation

    • The author, Toby Murray, is associate professor of cybersecurity, School of Computing and Information Systems, The University of Melbourne
    • This article is republished from The Conversation under a Creative Commons licence


    Crowdstrike CrowdStrike Falcon Toby Murray
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleGlobal outage grounds flights, hits media, banks, telcos
    Next Article TCS | Nomvuyiso Batyi on what needs fixing in SA telecoms

    Related Posts

    CrowdStrike, Delta sue each other over flight disruptions

    29 October 2024

    CrowdStrike apologises for Windows IT disaster

    25 September 2024

    Bookmarks | The music industry has a hard drive problem

    13 September 2024
    Company News

    Building a cyber-resilient culture from the boardroom to the front lines

    12 June 2025

    How South Africa’s municipalities are finally getting smart

    12 June 2025

    Ransomware roulette: pay up or power through?

    11 June 2025
    Opinion

    Beyond the box: why IT distribution depends on real partnerships

    2 June 2025

    South Africa’s next crisis? Being offline in an AI-driven world

    2 June 2025

    Digital giants boost South African news media – and get blamed for it

    29 May 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.