Disaster Recovery

CrowdStrike Speeding Up Remediation of Systems Hit by Blue Screen of Death

CrowdStrike tested a new technique to speed up the remediation of systems impacted by the recent bad update.

CrowdStrike on Monday informed customers that it has tested a new technique to speed up the remediation of systems impacted by the recent bad update, and the company claims many systems have already been restored.

Roughly 8.5 million Windows devices started displaying a Blue Screen of Death (BSOD) late last week after receiving a faulty update pertaining to CrowdStrike’s Falcon product. This led to one of the worst IT failures in history, causing significant outages across several industries, including aviation, financial, healthcare, and education.

Microsoft and CrowdStrike released tools and other resources to help impacted users restore systems, but it hasn’t been an easy task for affected organizations.

On Monday, CrowdStrike announced that a significant number of devices “are back online and operational” and the company has tested a new technique that should help accelerate remediation efforts.

“We’re in the process of operationalizing an opt-in to this technique,” the company said. 

It’s unclear exactly how many systems are still impacted. 

Advertisement. Scroll to continue reading.

Unsurprisingly, threat actors have started leveraging this incident for phishing, scams and malware delivery

CrowdStrike warned customers on Monday that its intelligence team came across a fake recovery manual designed to download a previously unknown stealer. 

The malware, now called Daolpu, is designed to collect credentials such as login data and cookies from the Chrome and Firefox browsers. The data is stored in a text file and sent to the attackers’ server. 

The cybersecurity giant has also learned of other types of malicious activity, such as phishing emails apparently coming from CrowdStrike support, staff being impersonated in phone calls, and the sale of fake automated recovery scripts.

Additional news coverage from SecurityWeek and around the web:

Related Content

Endpoint Security

CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw.

Compliance

A judge has ruled that the plaintiffs failed to demonstrate intent to defraud investors. 

Funding/M&A

News of the move to acquire Seraphic comes less than a week after CrowdStrike announced an agreement to acquire identity security startup SGNL for...

Funding/M&A

The deal aims to bolster CrowdStrike's Falcon platform with "continuous identity" protection to secure human and AI-driven access in real-time.

Cybercrime

The company has confirmed that it terminated an insider who shared screenshots of his computer with cybercriminals.

Management & Strategy

CrowdStrike became a global partner of Mercedes’ F1 team in 2019, but Kurtz’s purchase into the ownership group was his personally.

Funding/M&A

CrowdStrike says the acquisition will bring valuable technology to enhance its Falcon Next-Gen SIEM.

Endpoint Security

Microsoft is preparing a private preview of new Windows endpoint security platform capabilities to help antimalware vendors create solutions that run outside the kernel.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version