The global IT outage, which began on July 19, has now been resolved. CrowdStrike reported that as of 5 p.m. local time on Monday, July 29 (00:00 GMT, Tuesday), the affected computers were effectively back to normal.
The lawsuit seeks unspecified compensation for investors who held CrowdStrike shares between November 29 and July 29. It alleges that CrowdStrike executives defrauded investors by falsely assuring them about the robustness of their software updates.
The disruption caused by the outage was widespread, impacting businesses and services globally, including airlines, banks, and hospitals. In an interview with CNBC, Delta Air Lines CEO Ed Bastian stated that the outage cost the airline $500 million in lost revenue and passenger compensation. Delta has reportedly hired a prominent lawyer and is preparing to seek compensation from CrowdStrike.
In a detailed review of the incident, CrowdStrike identified a “bug” in a system designed to ensure the proper functioning of software updates. The company acknowledged that the glitch allowed “problematic content data” in a file to go undetected. CrowdStrike has stated that it will implement better software testing and more stringent checks to prevent a recurrence of the incident.
CrowdStrike’s Falcon software, widely used by businesses globally to protect against malware and security breaches, experienced a major issue when a routine content configuration update led to Windows crashes. The problematic update was intended to “gather telemetry on possible novel threat techniques” but instead caused widespread system failures.
The company typically issues configuration updates in two forms: Sensor Content updates, which directly update the Falcon sensor at the kernel level, and Rapid Response Content updates, which modify the sensor’s behavior to detect malware. The trouble stemmed from a small 40KB Rapid Response Content file.
CrowdStrike manages its own cloud system to validate content before release, aiming to prevent incidents like Friday’s crash. However, a bug in the Content Validator allowed one of two Template Instances to pass validation despite containing flawed data.
To avoid future incidents, CrowdStrike has committed to enhancing its Rapid Response Content testing procedures. This will include local developer testing, content update and rollback testing, along with stress testing, fuzzing, and fault injection. Stability and content interface testing will also be applied to Rapid Response Content.
Additionally, CrowdStrike will update its cloud-based Content Validator to better scrutinize Rapid Response Content releases, incorporating new checks to prevent problematic content from being deployed.


