CrowdStrike confirms Macs are 'not impacted' by a global outage impacting airlines, banks, and more — and a fix is on the way

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
Sucks to be a windows user
dbdabfa2390e4dcc02acbe9a99b7e1fb.png
 

EdwinG

Ambassador
Mar 10, 2012
4,319
750
113
Visit site
Sucks to be an ICT employee today. I feel for the Service Desk Technologists and Systems Administrators that will need to do some cleanup after this.

CrowdStrike will need to do an RCA and ensure this doesn’t happen again.

Even if it’s not Microsoft’s direct fault, I hope Microsoft prohibits kernel-level modules from being loaded in the future, but that’s going to take time if they do that - like 5-15 years easily.
 
  • Like
Reactions: Just_Me_D

Just_Me_D

Ambassador Team Leader, Senior Moderator
Moderator
Jan 8, 2012
60,154
762
113
Visit site
I wonder how many Enterprises will be switching to the mac
Companies, in my opinion, have been switching to Macs for quite some time. Having said that, it’s going to take several more outages like this to get big companies to set the money aside to switch completely over.
 
  • Like
Reactions: FFR

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
Companies, in my opinion, have been switching to Macs for quite some time. Having said that, it’s going to take several more outages like this to get big companies to set the money aside to switch completely over.

True, but if you remember it took a massive blackberry outage to kill the brand in the enterprise.

And this is a massive outage for Microsoft.
 

Just_Me_D

Ambassador Team Leader, Senior Moderator
Moderator
Jan 8, 2012
60,154
762
113
Visit site
True, but if you remember it took a massive blackberry outage to kill the brand in the enterprise.

And this is a massive outage for Microsoft.
From what I gather, Windows users who do not have their system set to auto-update are not affected — at least that’s what I’m being told.
 
  • Like
Reactions: FFR

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
From what I gather, Windows users who do not have their system set to auto-update are not affected — at least that’s what I’m being told.

Could be, but I have never seen this happen to Microsoft at this scale. Uk, Germany, France, Australia have all been affected.
 

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
Sucks to be an ICT employee today. I feel for the Service Desk Technologists and Systems Administrators that will need to do some cleanup after this.

CrowdStrike will need to do an RCA and ensure this doesn’t happen again.

Even if it’s not Microsoft’s direct fault, I hope Microsoft prohibits kernel-level modules from being loaded in the future, but that’s going to take time if they do that - like 5-15 years easily.

Didn’t Microsoft push out the update? That’s pretty much a direct fault.


From what I gather, Windows users who do not have their system set to auto-update are not affected — at least that’s what I’m being told.


It’s being reported a billion users are affected globally out of 1.4 billion windows users. That’s a more than a significant outage.
 

EdwinG

Ambassador
Mar 10, 2012
4,319
750
113
Visit site
From what I gather, Windows users who do not have their system set to auto-update are not affected — at least that’s what I’m being told.
It’s not a Windows update that caused it, but a content update for CrowdStrike’s EDR software. That software is also available for Macintosh and Linux systems, and it is usually installed for entreprises using CrowdStrike. Oh, and the updates, a user can’t disable them; only a security systems administrator can.

The resulting impact would be identical should a defective update have been made available for those systems. A pure kernel panic on boot.

Apple has improved their kernel module handling, but AFAIK it’s not 100% there yet. So, until the OS developers fully prohibit kernel-level modules, it’s going to occur again.

 
  • Like
Reactions: Just_Me_D

EdwinG

Ambassador
Mar 10, 2012
4,319
750
113
Visit site
Didn’t Microsoft push out the update? That’s pretty much a direct fault.
emoji23.png
As I posted, no they did not. It’s a different company altogether, CrowdStrike.

If the system is not running CrowdStrike Falcon Sensor on a Windows operating system, it’s not going to have this specific issue.

It can also affect macOS and Linux in the same manner, because guess what, CrowdStrike Falcon Sensor is also available for those two series of operating systems.
 

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
It’s not a Windows update that caused it, but a content update for CrowdStrike’s EDR software. That software is also available for Macintosh and Linux systems, and it is usually installed for entreprises using CrowdStrike. Oh, and the updates, a user can’t disable them; only a security systems administrator can.

The resulting impact would be identical should a defective update have been made available for those systems. A pure kernel panic on boot.

Apple has improved their kernel module handling, but AFAIK it’s not 100% there yet. So, until the OS developers fully prohibit kernel-level modules, it’s going to occur again.


No one said it was a windows update.

Microsoft pushed out the update, that’s what’s being reported.

The solution that is currently being presented was to boot into safe mode, locate a file delete and reboot, that doesnt require a security system admin.

Of and the Mac wasn’t affected, it’s right there on the title to the thread
 

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
As I posted, no they did not. It’s a different company altogether, CrowdStrike.

If the system is not running CrowdStrike Falcon Sensor on a Windows operating system, it’s not going to have this specific issue.

It can also affect macOS and Linux in the same manner, because guess what, CrowdStrike Falcon Sensor is also available for those two series of operating systems.

As I posted earlier, Microsoft pushed the update , to windows users not crowd strike.

And the Mac is not affected, see title of the thread.
 

EdwinG

Ambassador
Mar 10, 2012
4,319
750
113
Visit site
No one said it was a windows update.

Microsoft pushed out the update, that’s what’s being reported.
NO!

That’s not what happened. Microsoft didn’t push out that software update. It’s NOT Microsoft software.

CrowdStrike pushed out an update using THEIR update mechanism: https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/

The solution that is currently being presented was to boot into safe mode, locate a file delete and reboot, that doesnt require a security system admin.
I said: “the updates, a user can’t disable them; only a security systems administrator can” That’s because update configuration are managed in a central console server.

A systems administrator can reboot and remove the affected file per CrowdStrike’s instructions because:
  1. The updated has been rolled back
  2. This is a local action. It does not disable updates.
The software will update upon reboot.
Of and the Mac wasn’t affected, it’s right there on the title to the thread
I know! And that’s because we were lucky. I’m stating that the macOS and Linux operating systems are AS vulnerable to this situation AS Windows.
 

FFR

Well-known member
Nov 7, 2012
3,532
484
83
Visit site
NO!

That’s not what happened. Microsoft didn’t push out that software update. It’s NOT Microsoft software.

CrowdStrike pushed out an update using THEIR update mechanism: https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/


I said: “the updates, a user can’t disable them; only a security systems administrator can” That’s because update configuration are managed in a central console server.

A systems administrator can reboot and remove the affected file per CrowdStrike’s instructions because:
  1. The updated has been rolled back
  2. This is a local action. It does not disable updates.
The software will update upon reboot.

I know! And that’s because we were lucky. I’m stating that the macOS and Linux operating systems are AS vulnerable to this AS Windows.

“The Microsoft Outage”
“The Microsoft Outage, biggest in IT history”

Macs unaffected.

418e74ce16898375402de8930c097dfc.png

a994a10edb06fd9883237f7d0bddd96c.png
 

Forum statistics

Threads
261,508
Messages
1,771,039
Members
441,317
Latest member
mobilezmarket