Initiativen für
Als nationale Behörde für Cybersicherheit hat das ZCB mehrere Initiativen für bestimmte Zielgruppen entwickelt, die hier vorgestellt werden.
Reference:
Advisory #
Version:
1.0
Affected software:
CrowdStrike Agent
The CCB received information that the update for csagent.sys from CrowdStrike is causing blue screen loops. (BSOD) CCB recommends not to execute the update for the CrowdStrike agent until a verified fix is available.
Update
https://www.crowdstrike.com/blog/statement-on-windows-sensor-update/
CrowdStrike has identified and addressed a defect in a recent content update affecting Windows hosts.
This defect caused crashes and blue screen errors related to the Falcon Sensor.
Crowdstrike confirms this is NOT a Security Breach, but a technical error
Mac and Linux hosts are unaffected
Hosts running Windows 7/2008 R2 are not impacted
Current Status:
The faulty channel file 291 has been reverted and we hope that this will mitigate further expansion. For already crashing systems, some are rebooting to a normal working state, and we believe they should pick the new channel file 3) Some systems are just loop crashing and might need a manual intervention.
Workaround Steps for individual hosts:
Reboot the host to give it an opportunity to download the reverted channel file. If the host crashes again, then:
Remark: Bitlocker-encrypted hosts may require a recovery key.
option 2:
Update