CrowdStrike Release Notes
52 release notes curated from 121 sources by the Releasebot Team. Last updated: Oct 1, 2026
CrowdStrike Products
- Oct 1, 2026
- Date parsed from source:Oct 1, 2026
- First seen by Releasebot:Oct 1, 2026
CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS
Crowdstrike expands Falcon Next-Gen SIEM into CISA’s SIEMaaS stack, giving eligible federal agencies a funded path to modernize SOC operations, unify security data, and extend existing EDR investments with faster investigation and response.
Turn Visibility into Action
CISA has called SIEM-as-a-service (SIEMaaS) “the Rosetta Stone” for visibility for good reason. Federal defenders need to see what is happening across increasingly complex environments, understand what matters, and turn that context into action before an adversary achieves its objective.
CrowdStrike Falcon® Next-Gen SIEM is now part of CISA’s SIEMaaS technology stack, which gives eligible agencies a fully funded path to modernize security operations through the Continuous Diagnostics and Mitigation (CDM) Dynamic and Evolving Federal Enterprise Network Defense (DEFEND) Group F shared service. Participating agencies can now deploy Falcon Next-Gen SIEM and extend existing CrowdStrike endpoint detection and response (EDR) investments into agency-wide security operations without using their own program funding.
This offering is available to CDM agencies that participate in CISA’s Persistent Access Capability program and already use CrowdStrike for EDR. Through the DEFEND F mechanism, Falcon Next-Gen SIEM SKUs are acquired on behalf of participating agencies.
For those agencies, Falcon Next-Gen SIEM can serve as the agency-wide SIEM to help teams unify security data, reduce operational complexity, and detect, investigate, prioritize, and respond to threats faster.
Turn Visibility into Action
Visibility alone is not the outcome. Federal security teams need context to distinguish signals from noise, understand malicious activity across their environment, and stay ahead of adversaries.
Falcon Next-Gen SIEM, delivered through the FedRAMP High-authorized CrowdStrike Falcon® platform in GovCloud, creates a unified security data layer across CrowdStrike and third-party telemetry. It brings together endpoint, identity, cloud, network, edge, and other security data while applying CrowdStrike threat intelligence, AI-powered analytics, and adversary-driven detections.
Falcon Platform Indicators of Attack (IOAs) extend CrowdStrike-managed behavioral detections across Falcon and third-party telemetry to help agencies identify emerging adversary behavior while reducing the burden of continually creating and maintaining detection logic.
Reduce the Cost and Burden of SOC Modernization
Federal CISOs face a difficult equation: Adversaries are moving faster while security teams contend with growing data volumes, siloed tools, limited resources, and legacy architectures.
The average eCrime breakout time was only 29 minutes in 2025, according to the CrowdStrike 2026 Global Threat Report, and AI-powered adversaries continue to accelerate. This makes machine-speed investigation essential. Falcon Next-Gen SIEM helps agencies meet that challenge by unifying security data and adversary intelligence, accelerating investigation, and giving defenders the context to act before an adversary achieves its goal.
For agencies already running CrowdStrike EDR modules, DEFEND F SIEMaaS provides a funded path to extend the security foundation already in place into broader SOC modernization. Falcon Next-Gen SIEM helps agencies gain the visibility, context, and speed to turn security data into action. Its capabilities include:
- Modernizing the SOC without using agency program funding: Falcon Next-Gen SIEM SKUs are acquired on behalf of participating agencies through DEFEND F SIEMaaS.
- Reducing SIEM cost and complexity: Retain security data for months or years at up to 80% less cost than legacy SIEMs through an index-free architecture.
- Putting adversary intelligence into action: Apply CrowdStrike threat intelligence and platform IOAs across first- and third-party security data.
- Accelerating investigations: Correlate activity across security domains and reduce time spent moving between tools and manually reconstructing attacks.
- Increasing analyst capacity: CrowdStrike AI capabilities automate repetitive SOC work while preserving analyst control. Teams can use natural language to surface context and intelligence, direct workflows, and accelerate investigations through Response Agent guidance trained on CrowdStrike Falcon® Complete managed detection and response (MDR) expertise. Documented customer outcomes include 3x faster mean time to respond and 70% less manual work.
- Building on existing EDR investments: Extend CrowdStrike capabilities already deployed into broader, more integrated security operations.
Availability
Falcon Next-Gen SIEM is available through CGI Federal’s CDM DEFEND F SIEMaaS shared service to eligible federal civilian agencies that use CrowdStrike EDR modules and participate in CISA’s CDM Persistent Access Capability program.
Through the DEFEND F mechanism, Falcon Next-Gen SIEM SKUs are acquired on behalf of participating agencies, allowing eligible agencies to access the capability without using their own program funding.
Contact your CrowdStrike Federal Account Team today to learn how your agency can access Falcon Next-Gen SIEM through CDM and schedule a tailored engagement.
Original source - Sep 29, 2026
- Date parsed from source:Sep 29, 2026
- First seen by Releasebot:Sep 30, 2026
falcon-self-hosted-registry-assessment-1.9.0
falcon-helm updates the Helm chart for CrowdStrike Self-hosted Registry Assessment 1.9.
CrowdStrike Self-hosted Registry Assessment
What's Changed
- feat(shra): update helm chart for 1.9 by @crwd-etatarevic in #548
Full Changelog: falcon-image-analyzer-1.2.1...falcon-self-hosted-registry-assessment-1.9.0
Original source All of your release notes in one feed
Join Releasebot and get updates from CrowdStrike and hundreds of other software products.
- Sep 17, 2026
- Date parsed from source:Sep 17, 2026
- First seen by Releasebot:Sep 17, 2026
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
Crowdstrike introduces SafeMind and its Frontier AI Readiness and Resilience Service, a closed-loop AI security system that pairs Red Tempest and Blue Solano to co-evolve attacks and detections. It promises stronger validation, faster detection creation, and lower cost at scale.
The Architecture: Three Interlocking Pieces
The conventional approach to AI-powered security is to build an offensive agent to find weaknesses, build a defensive agent to catch threats, and run them in separate tracks. It's a clean division of labor that produces capable tools. However, the conventional approach also produces a permanent blind spot — the defense is never trained against the actual offense, and the connective tissue between the two is manual, slow, and fragile.
With adversarial AI capable of generating and launching thousands of unique attacks at machine speed, this blind spot poses a significant and immediate risk to the enterprise.
SafeMind is CrowdStrike's answer to that gap. Developed through research conducted by the CrowdStrike Cyber Superintelligence Lab, SafeMind is a closed-loop system where offense and defense continuously sharpen each other through a process called adversarial co-evolution. The result is a defense that's been forged against the best possible attacks, run by an adversary that knows every detail of the defensive setup. This results in 70% improved accuracy, 99% cost reduction, and 6x faster detection creation that can occur autonomously at scale on new attacks.
SafeMind is built on three components: a high-fidelity Cyber Agent Environment that hosts an offensive agent (Red Tempest) and a defensive agent (Blue Solano) locked in continuous adversarial competition.
The Cyber Agent Environment
For adversarial co-evolution to mean anything, the agents must be orchestrated within realistic environments. CrowdStrike built the SafeMind system to deploy Cyber Agent Environments that are representative of enterprise environments. When we establish each Cyber Agent Environment, we aim to have the minimum necessary to accomplish our purpose. The system anchors on ingesting network maps and telemetry from the CrowdStrike Falcon® platform to produce a high-fidelity slice of a real environment. Each attack scenario can run more than 10,000 times to build statistically meaningful coverage.
Red Tempest
Red Tempest pursues the full attack lifecycle of network discovery, vulnerability enumeration, exploitation, privilege escalation, lateral movement, and persistence, across over 1,000 distinct attack scenarios covering 155 MITRE ATT&CK® techniques. These are long-horizon campaigns where the agent takes thousands of sequential actions across multiple consecutive runs to achieve a given objective, whether that's data exfiltration or some other form of compromise.
Under the hood, Red Tempest is a 27-billion-parameter dense model running in a multi-agent harness built around an orchestrator and swarm architecture. A manager agent tracks the overall campaign and delegates to specialized subagents — recon, assault, and others — each handling distinct phases of the operation. The offense utilizes CrowdStrike’s deep threat intelligence knowledge base containing hundreds of apex adversaries and their associated tactics, techniques, and procedures (TTPs). The context window runs at 256K tokens and can extend to 1 million. This matters because a long-running offensive campaign generates enormous amounts of state that the agent needs to reason over continuously.
Blue Solano
Blue Solano is the defensive counterpart. It operates as a custom agentic harness built around NVIDIA Nemotron Ultra as the reasoning orchestrator and a purpose-built detection generation model, post-trained on CrowdStrike's own detection engineering data.
When Red Tempest completes an attack, Blue Solano ingests the full attack trace. The orchestrator analyzes the attack description and techniques used, then queries live Falcon sensor telemetry to reconstruct what actually happened on the endpoint. Blue Solano doesn't generate detections from documentation or templates. It works against the real telemetry the attack produced, confirming what the sensor captured before writing the detection logic.
The detection generation model is a post-trained NVIDIA Nemotron Super 120B mixture-of-experts model with 12 billion active parameters. It was first trained using supervised fine-tuning on CrowdStrike's internal detection engineering corpus, encoding the equivalent of 3.1 million working hours of expertise. It was then further trained with reinforcement learning in an environment where Red Tempest attacks served as the reward signal: The model was rewarded for generating detections that caught the attack and penalized for any that produced false positives on clean data. The defense was literally trained against the offense.
On new attacks, Blue Solano calls this model to generate candidate detections, then validates them against live telemetry to confirm they catch the attack and checks them against clean baseline data to ensure they don't fire on normal activity. The output is not a report or recommendation but working detection logic. In the live SafeMind loop, Blue Solano faces attacks it has never seen before and writes the defenses for them on the spot.
The Loop That Makes It Work
Here's what makes SafeMind more than two powerful agents running in parallel.
We start by establishing the Cyber Agent Environment given to Red Tempest. From here, agent orchestration executes. Kubernetes pods with SafeMind agents deploy at scale, and the loop initiates.
When Blue Solano successfully blocks Red Tempest, the system doesn't just log the outcome. It uses Blue Solano's new detections to harden the environment, then challenges Red Tempest to execute again with complete knowledge of every defensive change that was made.
This is a deliberately brutal test. The cycle continues until a defined level of friction/cost is imposed on Red Tempest. At that point, the defenses have been validated against the hardest version of the adversary, one with total information.
What the Numbers Show
On the offensive side, Red Tempest achieves 100% compromise at roughly one-fifth the cost of comparable models on our internal benchmarks:
Table 1. Red Tempest cost to achieve 100% compromise compared to cost for comparable models
Model | Cost to 100% Compromise
Off-the-shelf closed frontier model | $96
Off-the-shelf open model | $62
Red Tempest (specialized harness) | $21An 80% cost reduction is a decisive, game-changing factor for defense. An adversarial co-evolution loop that costs $96 per offensive cycle can't run continuously. One that costs $21 can.
Blue Solano achieves a 70% relative improvement in accuracy over general-purpose harnesses orchestrated by frontier models, while reducing the cost of generating a detection from ~$10 to $0.03.
Performance here is measured by a strict combined metric across our internal benchmarks of previously unseen attack scenarios from Red Tempest. A detection passes only if it catches the attack and produces no significant noise when tested against clean production data. Both conditions must hold. A detection that finds the threat but floods analysts with false positives fails, just as a narrow detection that misses the attack does.
General-purpose harnesses, even when powered by frontier models, tend to cluster at higher cost and lower accuracy. The same security harness running off-the-shelf frontier models lands in the middle. Blue Solano, powered by the post-trained custom model, sits alone in the top right. The time gap tells a similar story. Blue Solano generates a validated detection in under 6 minutes. General harnesses average over an hour.
The economics of always-on autonomous defense also depend on that cost number. At $10 per detection, continuous automated defense is cost-prohibitive. At $0.03, it isn't.
Why Adversarial Co-evolution Matters
Adversaries no longer iterate on attacks manually. They are evolving to use the best off-the-shelf agents they can get in order to scale attacks today. The agent-state is shrinking the gap in capabilities between the apex adversaries and everyone else.
SafeMind is designed for the world where that's already the case. The defense loop runs continuously against the best-in-class offensive agent, improves with every cycle, and is validated against an attacker that has complete knowledge of the defensive playbook. The goal isn't to find every attack in advance, but to build defenses that hold even when the adversary knows exactly what you built.
The best security isn't the kind where you hope the adversary doesn't find your weaknesses. It's the kind where you hand them the blueprint and they still can't get through.
A First Look at SafeMind’s Functionality
The initial offering for CrowdStrike SafeMind is the Frontier AI Readiness and Resilience (FAIRR) Service, powered by Red Tempest. Red Tempest’s code review capability is one model-and-harness configuration built to systematically identify vulnerabilities in custom applications and their underlying software dependencies.
CrowdStrike will leverage Blue Solano and Red Tempest to serve as foundational components for future product offerings, while also enhancing the delivery of new and existing services.
Additional Resources
- Watch Fal.Con 2026: Future Innovation | Bartley Richardson & Alex Ionescu.
- Learn more about CrowdStrike’s Frontier AI Readiness and Resilience Service (FAIRR).
- Read about Benchmaxxing: When Benchmark Becomes the Target.
- Learn more about the CrowdStrike Cyber Superintelligence Lab.
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 4, 2026
The CrowdStrike Cyber Superintelligence Lab
Crowdstrike launches the Cyber Superintelligence Lab and SafeMind, a new AI-driven cyber defense effort that brings frontier research into the Falcon platform with autonomous offense and defense, powered with NVIDIA partnership.
ANNOUNCING
The CrowdStrike Cyber Superintelligence Lab
The first frontier AI research organization built for cyber defense and AI safety.
The lab's mission
Build cyber defense that learns faster than adversaries evolve
The Cyber Superintelligence Lab unites CrowdStrike’s AI researchers, offensive operators, and incident responders with unmatched security data, adversary intelligence, and high-fidelity environments to build the next generation of cyber defense.
The first breakthrough: SafeMind
CrowdStrike SafeMind, in partnership with NVIDIA, is a family of purpose-built security models and agentic harnesses that bring autonomous offense and defense together. Red Tempest finds the weakness. Blue Solano closes it. The system learns.
See CrowdStrike SafeMind in Action
From frontier research to real-world protection.
The Cyber Superintelligence Lab is operating today. SafeMind brings its research directly into the Falcon platform, turning advances in AI into real-world protection for customers.
Every breach we’ve stopped has trained the model, and every breach we’ll stop makes the model stronger.
George Kurtz
CEO & Founder, CrowdStrikeFAQs
What is the Cyber Superintelligence Lab?
What is CrowdStrike SafeMind?
How does SafeMind work?
What are Red Tempest and Blue Solano?
What are the SafeMind harnesses?
How does the Cyber Superintelligence Lab safely train and test autonomous AI?
What is NVIDIA’s role?
Original source - Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 2, 2026
CrowdStrike Delivers the Next Evolution of the Agentic SOC
Crowdstrike introduces the next evolution of its agentic SOC with new Falcon platform capabilities for unified data, coordinated expert agents, and a single workspace to build and govern automation. Highlights include certified data pipelines, detection in the pipeline, agentic investigations, and agentic SOAR.
The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real time.
CrowdStrike is delivering new innovations with the next evolution of the agentic SOC, in which analysts and AI agents work together in a unified system.
In the legacy SOC, evidence lives in disconnected systems. Automation is split across separate interfaces and execution logs. Analysts toggle between tools and manually stitch together context. Only a subset of detections receives real investigation while everything else piles up as a structural blind spot.
But most security teams struggle to achieve an agentic SOC transformation, for three key reasons. First, fragmented data prevents cross-domain investigations. When context lives in separate tools and isn't AI-ready, agents can't connect the dots across identity, cloud, endpoint, SaaS, and network. Second, isolated agents reach incorrect or late verdicts. Because they work in silos with sequential handoffs, they see only a partial picture, which reverts the work back to analysts. Third, ungoverned automation creates breach points. Agents act in your environment and connect to your systems; if you can't build, monitor, and control them, you can't see what's running, what it's connected to, or what it costs.
CrowdStrike takes a different path. The CrowdStrike Falcon® platform is not just where agents run. It is where the data is generated, enriched, investigated, orchestrated, and governed.
New at Fal.Con 2026: The Evolution of the Agentic SOC
At Fal.Con, CrowdStrike is delivering the next evolution of the agentic SOC, a production operating model where expert agents and analysts stop breaches as one system. New capabilities in the Falcon platform include:
- A more unified foundation: Third-party data now arrives detection-ready through certified pipelines, with detection logic running inside the pipeline before data reaches its destination. This accelerates both time-to-value and mean time to detect (MTTD).
- Coordinated teams of specialist agents: For actions ranging from cross-domain investigations to proactive reconnaissance, teams can deploy fleets of battle-tested agents built by CrowdStrike experts and coordinated by an orchestrator agent, all of which work out of the box.
- A unified agentic SOAR workspace. Charlotte AI AgentWorks, SOAR orchestration, and CrowdStrike Falcon® Foundry converge in one place to build and govern rule-based and agentic automation alike, with expanded flexibility for how security teams can build agents and connect them to their security stack via MCP.
See it in action: Coordinated expert agents investigate every domain at once and converge on a single verdict
Let’s take a closer look at what’s new.
Certified Data, Ready for Agents
The Falcon platform starts from native telemetry and extends outward, delivering petabytes of cross-domain data refined by elite security experts in one unified foundation. Teams decide what is ingested and what is federated, and critical first-party data has no ingestion cost. The result is agents with a complete view of their environment that is AI-ready from the start.
Third-party data traditionally depends on pipelines customers build and maintain themselves, with no guarantee that data lands complete or usable. A single dropped field or schema change can break a detection without anyone noticing. In an agentic SOC, where agents act on data automatically, that risk compounds.
CrowdStrike is closing this gap with new capabilities that optimize how third-party data gets in, what happens to it in flight, and whether teams can trust it when it lands. These include:
- Certified data pipelines (Public Preview). Teams will get pre-built, pre-tested data flows that CrowdStrike validates and maintains, starting with Zscaler and Palo Alto Networks. Sources go live in hours and arrive detection-ready, so coverage starts when a new source is connected. There is no pipeline overhead to carry, and only security-relevant data reaches the platform.
- Detection in the pipeline (Public Preview). Detection normally waits until data is ingested and normalized. With this new capability, detection logic will run inside the pipeline itself. Because pipelines can execute at the edge, threats are caught in transit, which reduces MTTD.
Coordinated Expert Agents That Know Your Environment
Agents need intelligent coordination that summons the right expertise at the right time. CrowdStrike now delivers out-of-the-box multi-agent workflows that coordinate teams of expert agents to accomplish tasks. These agents reason over shared context unique to each organization and sharpen their accuracy over time. These coordinated workflows span critical security operations, from investigations to digital risk protection.
New capabilities include:
- Agentic investigations with shared context (Public Preview). When detections warrant an investigation, an orchestrator agent summons specialist agents, built and used every day by CrowdStrike Falcon® Complete managed detection and response. These agents work across every associated domain and data source in parallel. They build on each other's findings through shared context and converge on a single verdict. From there, they drive the next step: clearing queues, or escalating with pre-assembled context for human review. Coverage no longer depends on who is available.
- Agentic Recon (Public Preview). As frontier AI accelerates how quickly adversaries can identify exposed credentials, leaked data, impersonation, and other paths into the enterprise, coordinated intelligence agents continuously investigate threats across the open, deep, and dark web. They turn natural language questions into targeted queries, assess related findings and impact, and recommend actions for mitigation and response. Security teams can move from manual triage to continuously uncovering and acting on exposures before adversaries can use them to gain access.
CrowdStrike's agents are shaped by two loops that compound over time. The first loop is global. Our agents are informed by millions of real detections from around the world and get sharper with every incident the Falcon Complete team stops.
Complementing that is a second, local loop. The same shared context layer that agents reason over during an investigation is where their learning accumulates. Every decision, correction, and resolution in a customer's environment is collected there, unique to that organization and accessible to all of their CrowdStrike agents. This improves agents’ accuracy over time.
With access to global expertise defeating adversaries anywhere, and local knowledge to operate fluently in a specific environment, CrowdStrike's agents continually improve accuracy and earn the trust to run at scale.
One Workspace to Build and Govern Automation
Building agents is one thing; operating them at scale is another. Charlotte Agentic SOAR now lets teams build and govern automation, both rule-based and agentic, in a single place with expanded flexibility.
New capabilities include:
- Unified agentic SOAR workspace (Public Preview): A new interface to build and govern automation enables teams to build with Charlotte AI AgentWorks, SOAR orchestration, and Falcon Foundry in a single UI. For each workflow, teams can define the triggers, data, conditions, agents, and actions. They can set what is fully automated or requires approval, and connect to the tools of their choice.
- Bring your own model (GA): Teams can use their existing OpenAI and Anthropic licenses to match the right AI model to each job. This allows them to optimize for reasoning complexity, latency, or cost, resulting in a more flexible and economical way to build, test, and run agents.
- Connect to any tool, any agent (GA): Third-party agents can now connect into Falcon tools through a CrowdStrike-managed MCP server, while Charlotte AI AgentWorks agents can reach out to the tools and data that security teams already run. The existing stack automatically becomes part of the agentic SOC. Agents reach the data they need wherever it lives and act through the tools teams already use; no overhaul required.
- Hybrid Analysis, reengineered (Public): As CrowdStrike’s community malware analysis tool, Hybrid Analysis helps security teams analyze suspicious files and connect findings to threat intelligence. Now reengineered with API-first access, it can plug directly into AI agent workflows, via an open-source MCP server, extending them with CrowdStrike malware analysis and intelligence.
The Agentic SOC: Only Possible on a Unified Platform
The agentic SOC is the operating model that connects the data, detection, investigation, orchestration, and response capabilities already deployed across the Falcon platform. Agentic investigations, delivered through CrowdStrike Falcon® Next-Gen SIEM and powered by Charlotte AI, run on existing Falcon telemetry with no new sensors required. They draw on signals from CrowdStrike Falcon® Next-Gen Identity Security and CrowdStrike Falcon® Cloud Security alongside endpoint data.
Each layer makes the next stronger. Better data produces faster, more accurate investigations, which in turn permit more informed workflow decisions. Governed workflows turn intelligence into accountable action.
The value of AI in security is enabling every investigation to begin with the right data, reason across the full attack, and produce an outcome defenders can trust. Only CrowdStrike brings together native and third-party data, agents built by the experts who stop breaches every day, a context layer that learns each environment, and governed orchestration in one platform. The agentic SOC from CrowdStrike is the operating model modern security demands.
Additional Resources
- Want to learn more about how CrowdStrike delivers the agentic SOC? Visit the Agentic SOC Transformation solution page.
- Want to learn more about Falcon Next-Gen SIEM? Visit the Falcon Next-Gen SIEM product page.
- Establish real-time telemetry control to streamline onboarding and route high-fidelity data across SIEM, AI, storage, and analytics with Falcon Onum.
Forward-Looking Statements
This blog may include discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.
Original source Similar to CrowdStrike with recent updates:
- Docusign release notes24 release notes · Latest Sep 15, 2026
- Anthropic release notes870 release notes · Latest Oct 6, 2026
- Ubiquiti release notes990 release notes · Latest Oct 6, 2026
- n8n release notes71 release notes · Latest Oct 6, 2026
- Cursor release notes138 release notes · Latest Oct 6, 2026
- Canva release notes41 release notes · Latest Jun 24, 2026
- Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 1, 2026
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
Crowdstrike introduces Falcon Guardian, extending AI detection and response with runtime security for AI agents. It adds agent discovery, prompt-to-runtime visibility, investigation and control, plus planned AI gateway, cross-domain hunting, MDR, and Next-Gen SIEM support.
Secure AI Agents Where They Execute
AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches.
This shift demands a new approach to AI security. Traditional tools can discover AI assets, govern access, or inspect individual interactions, but they were not designed to connect agent activity with the downstream system actions they trigger. Securing the agentic enterprise requires visibility and control at agent runtime.
CrowdStrike is introducing CrowdStrike Falcon® Guardian, the evolution of Falcon AI Detection and Response (AIDR) and CrowdStrike’s flagship solution for the AIDR category. Falcon Guardian includes Falcon AIDR’s AI visibility, governance, data protection, and threat detection and response capabilities across endpoint, cloud, and SaaS environments, while introducing powerful new capabilities to comprehensively discover, investigate, and secure AI agents on the endpoint, where AI executes.
Falcon Guardian will include a new AI gateway capability to provide a centralized control and monitoring point for enterprise AI traffic. CrowdStrike is also extending our elite security services, expanding support for cross-domain threat hunting and managed detection and response (MDR) to Falcon Guardian.
With Falcon Guardian, CrowdStrike is extending our runtime security architecture into the agentic layer. Falcon Guardian fuses AI agent activity with CrowdStrike Falcon® platform endpoint telemetry to establish a direct causal chain from prompt to runtime behavior and impact. This gives security teams the context to understand what agents do, investigate AI threats and their blast radius, and respond before threats spread.
Built on the Falcon platform, Falcon Guardian combines continuous agent discovery with runtime visibility, investigation, and control to help organizations understand which AI agents are operating and what they do. New capabilities include:
- Discover shadow AI agents: Falcon Guardian continuously discovers known and previously unknown AI agents across supported Windows, macOS, and Linux endpoints. It identifies where they are running, who is using them, and their security status.
- Connect AI activity to runtime impact: Falcon Guardian fuses AI agent activity with Falcon endpoint telemetry to connect prompts, skill use, tool calls, MCP servers, and identity with downstream system execution for supported agents. This establishes prompt-to-runtime-behavior that shows security teams what an agent was asked to do and what happened.
- Turn AI governance into runtime control: Falcon Guardian enables organizations to define which supported AI agent types are permitted to operate on managed endpoints, helping security teams sanction approved agents and prevent unauthorized agent types from running. Existing Falcon Guardian controls continue to protect supported AI interactions against threats such as prompt injection and sensitive data exposure.
- Investigate threats to agents, determine blast radius, and stop breaches: Falcon Guardian reconstructs agent sessions and downstream execution into a unified causal investigation, allowing analysts to trace suspicious activity across affected agents and systems. Teams can quickly pivot to related activity to understand the scope of exposure and drive automatic containment by blocking malicious agent behaviors and compromised assets at runtime across agents.
Falcon Guardian’s new AI agent security capabilities build on a broader foundation of AI protection. It continues to help organizations discover shadow AI across endpoint, cloud, and SaaS environments, govern access to models and AI tools, protect sensitive data, and detect AI-specific threats. This foundation protects both workforce AI adoption and enterprise-developed AI systems.
Extend Falcon Guardian with an AI Gateway
As AI applications and agents communicate with a growing ecosystem of models, services, and MCP infrastructure, organizations need a consistent way to monitor and govern AI traffic beyond the endpoint.
Falcon Guardian will soon include a native AI gateway capability, offering a new centralized control point for enterprise AI traffic and will provide expanded visibility, access management, and policy enforcement as applications and agents communicate with AI models and services. The gateway feature will also use context from the Falcon platform, including the user, agent, endpoint, identity, asset, and security posture, to inform policy decisions.
This new capability is currently pre-beta and will go to GA next quarter (Q4).
Extend Expert-Led Defense to AI
As AI agents operate autonomously across enterprise environments, organizations need the expertise to identify suspicious behavior, uncover emerging adversary tradecraft, and respond when AI systems are targeted or compromised. CrowdStrike is extending managed cross-domain threat hunting and MDR services to Falcon Guardian, bringing expert-led defense to AI applications and autonomous agents.
Falcon Adversary OverWatch Hunts Threats Targeting AI Agents
CrowdStrike Falcon® Adversary OverWatch™ Cross-Domain, available today, extends 24/7 proactive threat hunting to AI applications and autonomous agents using Falcon Guardian’s runtime context. CrowdStrike’s expert hunters combine this rich behavioral context with frontline adversary intelligence to uncover manipulation, abuse, and emerging tradecraft that automated detections may miss.
This helps security teams identify and disrupt adversaries before they can expand access and escalate AI activity into a broader intrusion.
Customers must have both Falcon Adversary OverWatch Cross-Domain and Falcon Guardian.
Falcon Complete MDR for the AI Era
CrowdStrike is also announcing CrowdStrike Falcon® Complete for Falcon Guardian to extend CrowdStrike’s industry-leading MDR service to AI applications and autonomous AI agents.
Falcon Complete for Falcon Guardian will deliver continuous, expert-led detection, investigation, and response for AI agents. CrowdStrike’s elite analysts will use Falcon Guardian’s rich runtime context to assess agent intent, distinguish legitimate AI activity from malicious behavior, and stop attacks in real time. With CrowdStrike analysts monitoring AI environments 24/7, customers can realize the full operational value of Falcon Guardian with expert protection around the clock.
This new service will be available to customers later this quarter (Q3).
Falcon Next-Gen SIEM Delivers Scalable, Cost-Effective Agent Data Capture
AI agents generate orders of magnitude more telemetry than traditional applications or human users. Routing this volume to third-party SIEMs can cause ingest costs to spiral out of control.
Falcon Guardian natively exports agent telemetry into CrowdStrike Falcon® Next-Gen SIEM as first-party data, pre-mapped to its schema for immediate correlation, detection, and automation, and correlated with identity, cloud, and SaaS data across the Falcon platform for cross-domain investigations. Since Falcon Guardian data is treated as first-party data rather than a separate ingest-based line item, this integration can eliminate potentially millions in annual third-party SIEM costs with agent telemetry, with default retention included to support compliance-ready visibility into AI agent activity.
CrowdStrike Defines the Next Generation of AI Security
Falcon Guardian brings discovery, governance, data protection, runtime security, investigation, and response together in CrowdStrike’s flagship solution in the AIDR market category, extending protection from AI interactions into the new agent execution layer.
CrowdStrike pioneered detection and response for the endpoint. Today, we are defining the AIDR category and applying that same focus on deep visibility, rich security context, and decisive response as we did with endpoint detection and response (EDR). With Falcon Guardian, organizations can build a stronger foundation to accelerate secure AI adoption and innovation.
Disclaimer
This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.
Original source - Aug 24, 2026
- Date parsed from source:Aug 24, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-platform-1.5.1
falcon-helm adds a comprehensive Helm umbrella chart for deploying the CrowdStrike Falcon platform on Kubernetes.
A comprehensive Helm umbrella chart to deploy the complete CrowdStrike Falcon platform for Kubernetes runtime security
What's Changed
- CSPG-96791-IAR 1.0.26 changes by @cs-pvyas in #543
- chore(release): bump falcon-platform chart version for IAR update by @mr-jungchoi in #546
Full Changelog: falcon-platform-1.5.0...falcon-platform-1.5.1
Original source - Aug 24, 2026
- Date parsed from source:Aug 24, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-image-analyzer-1.2.1
falcon-helm ships a Helm chart update for Falcon Image Analyzer with a version bump for the IAR update.
A Helm chart for Falcon Image Analyzer
What's Changed
- CSPG-96791-IAR 1.0.26 changes by @cs-pvyas in #543
- chore(release): bump falcon-platform chart version for IAR update by @mr-jungchoi in #546
Full Changelog: falcon-image-analyzer-1.2.0...falcon-image-analyzer-1.2.1
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-sensor-1.37.0
falcon-helm releases updates for the CrowdStrike Falcon sensor Helm chart, adding a new Falcon config volume, Azure CSI secrets driver support, and sensor pod chart environment updates while also refreshing docs and chart versioning.
A Helm chart to deploy CrowdStrike Falcon sensors into Kubernetes clusters.
What's Changed
- feat(falcon-sensor): add new falcon config volume for daemonset by @mr-jungchoi in #531
- csi secrets driver support for azure and vault by @gpontejos-cs in #532
- chore(falcon-sensor): ignore node.backend option and add deprecation notice by @mr-jungchoi in #536
- chore: add us-3 by @gpontejos-cs in #537
- chore: add HELM_CHART env to all sensor pods by @mr-jungchoi in #538
- move falcon-sensor HELM_CHART env to configmap by @mr-jungchoi in #539
- docs: update node.backend docs to align with sensor docs by @mr-jungchoi in #540
- chore: remove vault csi driver support by @gpontejos-cs in #541
- docs: update secret management sections by @mr-jungchoi in #542
- chore(release): bump chart versions for sensor 7.40 release by @mr-jungchoi in #544
Full Changelog: falcon-sensor-1.36.0...falcon-sensor-1.37.0
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-platform-1.5.0
falcon-helm releases an updated Helm umbrella chart for deploying the full CrowdStrike Falcon platform for Kubernetes runtime security, with sensor and KAC updates, new config and secret management support, and probe timeout fixes.
A comprehensive Helm umbrella chart to deploy the complete CrowdStrike Falcon platform for Kubernetes runtime security
What's Changed
- feat(falcon-sensor): add new falcon config volume for daemonset by @mr-jungchoi in #531
- chore: rbac and default resource updates for KAC 7.40 by @mr-jungchoi in #535
- csi secrets driver support for azure and vault by @gpontejos-cs in #532
- chore(falcon-sensor): ignore node.backend option and add deprecation notice by @mr-jungchoi in #536
- chore: add us-3 by @gpontejos-cs in #537
- chore: add HELM_CHART env to all sensor pods by @mr-jungchoi in #538
- move falcon-sensor HELM_CHART env to configmap by @mr-jungchoi in #539
- docs: update node.backend docs to align with sensor docs by @mr-jungchoi in #540
- chore: remove vault csi driver support by @gpontejos-cs in #541
- docs: update secret management sections by @mr-jungchoi in #542
- chore(release): bump chart versions for sensor 7.40 release by @mr-jungchoi in #544
- fix: increase timeouts for kac watcher probes by @mr-jungchoi in #545
Full Changelog: falcon-platform-1.4.0...falcon-platform-1.5.0
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-kac-1.7.0
falcon-helm releases a new Helm chart update for CrowdStrike Falcon Kubernetes Admission Controller, adding support updates for CSI secrets drivers, US-3, sensor pod environment settings, and improved probe timeouts.
A Helm chart to deploy CrowdStrike Falcon Kubernetes Admission Controller.
What's Changed
- chore: rbac and default resource updates for KAC 7.40 by @mr-jungchoi in #535
- csi secrets driver support for azure and vault by @gpontejos-cs in #532
- chore: add us-3 by @gpontejos-cs in #537
- chore: add HELM_CHART env to all sensor pods by @mr-jungchoi in #538
- chore: remove vault csi driver support by @gpontejos-cs in #541
- docs: update secret management sections by @mr-jungchoi in #542
- chore(release): bump chart versions for sensor 7.40 release by @mr-jungchoi in #544
- fix: increase timeouts for kac watcher probes by @mr-jungchoi in #545
Full Changelog: falcon-kac-1.6.0...falcon-kac-1.7.0
Original source - Aug 13, 2026
- Date parsed from source:Aug 13, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-image-analyzer-1.2.0
falcon-helm releases Falcon Image Analyzer Helm chart updates with Azure secret support, US-3, and sensor pod refinements.
A Helm chart for Falcon Image Analyzer
What's Changed
- csi secrets driver support for azure and vault by @gpontejos-cs in #532
- chore: add us-3 by @gpontejos-cs in #537
- chore: add HELM_CHART env to all sensor pods by @mr-jungchoi in #538
- chore: remove vault csi driver support by @gpontejos-cs in #541
- docs: update secret management sections by @mr-jungchoi in #542
- chore(release): bump chart versions for sensor 7.40 release by @mr-jungchoi in #544
Full Changelog: falcon-image-analyzer-1.1.20...falcon-image-analyzer-1.2.0
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Jul 31, 2026
Falcon AIDR Now Protects Copilot Studio Agents and Claude Code
Crowdstrike adds Falcon AI Detection and Response support for Microsoft Copilot Studio, Claude Code, and the Falcon browser extension, expanding AI visibility, detection, and blocking for agent, developer, and browser activity with SIEM correlation and policy-based control.
New feature releases extend AI visibility, detection, and response capabilities to Microsoft Copilot Studio and Claude Code.
Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.
CrowdStrike Falcon® AI Detection and Response (AIDR) today is extending its AI visibility, detection, and response capabilities to Microsoft Copilot Studio and Claude Code.
Microsoft Copilot Studio: Stop Risky Tool Calls Before They Run
Copilot Studio lets teams build custom agents that reach into enterprise tools and data. That reach is a feature, but it's also an exposure: An agent can be prompted to call a tool that hands back something it shouldn't.
Falcon AIDR plugs into Copilot Studio as an external threat detection provider. Before an agent runs a tool, Falcon AIDR checks the tool name and its input parameters against the organization’s policy and returns an allow or block decision inside Copilot Studio's response window.
The payoff is a decision point inside the agent's workflow. If a manipulated conversation pushes an agent toward a tool the business policy forbids, Falcon AIDR blocks it before it executes. Checks are recorded on the Falcon AIDR Findings page, ready to correlate with the rest of the organization’s telemetry in CrowdStrike Falcon® Next-Gen SIEM.
See it in action:
Claude Code: Govern AI-assisted Development Without Interfering
Developers use Claude Code because it can interact with files, shell commands, and the network. Falcon AIDR now connects to Claude Code’s own hook event system to check, and block, prompts and tool activity as they happen. Setup is as simple as adding a block of JSON in the Claude Code settings file; there's no agent to install and nothing to add to the build, and the Falcon AIDR hook coexists with any hooks a team already runs.
Using this capability, developers keep their workflow, and security gains real visibility and control. A prompt carrying a secret or personally identifiable information (PII) gets caught before Claude ever sees it, a dangerous tool call gets stopped before it runs, and events can be tied back to a specific Claude Code session and user in Falcon Next-Gen SIEM.
Watch this short demo:
Falcon Browser Extension Gains AIDR Capability
Falcon AIDR support is now available in the Falcon browser extension, giving organizations monitoring and control for browser-based AI activity and creating a cleaner path to AI visibility and protection with a unified browser extension. Security teams can manage coverage through the Falcon console, align Falcon AIDR policy assignment with host groups they already use, and reduce the need for separate browser extension workflows, all resulting in faster coverage with less operational lift.
Because activity is tied back to Falcon sensor-provided endpoint data, AI detections in the browser include host and user context. With Falcon Next-Gen SIEM, teams can correlate AIDR findings with endpoint detection and response (EDR), identity, and network telemetry from the same machine, gaining a more complete view of workforce AI activity and the risk around it.
See how it works:
Secure AI Wherever It Runs
AI is acting with businesses’ data right now, and they need to see and shape this activity the moment it happens. These three feature releases further enhance visibility and control by feeding straight into the agentic SOC through Falcon Next-Gen SIEM.
Start by watching and reporting to learn how teams actually use AI. Turn on blocking and data transformation once the risk is identified. The same policy model reaches across the rest of Falcon AIDR, from workforce and agent protection to AI applications and the cloud. Wherever teams put AI to work next, they can bring visibility and control with them.
Schedule a demo to see Falcon AIDR in action.
Additional Resources
- Visit the Falcon AI Detection and Response product page
- Learn more about AIDR and CrowdStrike's vision for securing the agentic enterprise in this video on demand:
- Join us at Fal.Con 2026 as we bring together cyber leaders from across the industry to help secure the AI revolution.
- Jul 23, 2026
- Date parsed from source:Jul 23, 2026
- First seen by Releasebot:Sep 5, 2026
falcon-self-hosted-registry-assessment-1.8.0
falcon-helm updates the CrowdStrike Self-hosted Registry Assessment Helm chart for 1.8.
CrowdStrike Self-hosted Registry Assessment
What's Changed
- feat(shra): update helm chart for 1.8 by @crwd-etatarevic in #530
Full Changelog
falcon-platform-1.4.0...falcon-self-hosted-registry-assessment-1.8.0
Original source - Jul 8, 2026
- Date parsed from source:Jul 8, 2026
- First seen by Releasebot:Jul 9, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security
Crowdstrike introduces Falcon Secure Access, now available through the Falcon platform to extend browser-native protection into sessions for SaaS, internal apps, GenAI tools, unmanaged devices, and AI-powered browser workflows.
The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal web apps, admin consoles, collaboration tools, and AI services from anywhere, often across a mix of managed, unmanaged, and personally owned devices.
As they do, adversaries are increasingly targeting the browser session itself. They use phishing, malicious extensions, session hijacking, adversary-in-the-middle techniques, browser exploits, and AI-powered attacks to bypass controls that stop at the endpoint, network, or login event.
This shift has created a critical security gap. Legacy secure access tools such as virtual private networks (VPNs), virtual desktop infrastructure (VDI), security access service edge (SASE), cloud access security broker (CASB), and remote browser isolation were designed around networks, perimeters, traffic inspection, and static authentication. While they can play important roles, they fail to secure what happens inside the browser session, where credentials are entered, SaaS apps are used, sensitive data is shared, AI tools are accessed, and session tokens can be stolen.
CrowdStrike Falcon® Secure Access closes that gap. Now available for customers to purchase and deploy through the CrowdStrike Falcon® platform, Falcon Secure Access extends CrowdStrike’s AI-native protection into the browser session to help organizations secure access, identity, data, GenAI applications, AI-powered browser extensions, and unmanaged device workflows through a browser-native approach.
A Leader in Zero Trust Browser Security
CrowdStrike has been named Frost & Sullivan’s 2026 Global Enabling Technology Leader in Zero Trust Browser Security. This highlights CrowdStrike’s differentiated approach to securing the browser from within, rather than relying on network routing, dedicated browser replacement, or traditional browser extensions.
“The cybersecurity industry has long grappled with the challenge of securing browser-based activity without degrading performance or user experience,” Frost & Sullivan states in its report. “Falcon Secure Access addresses this challenge through a groundbreaking innovation: a JavaScript runtime security module injected at the engine level, rather than relying on traditional browser extensions.”
Falcon Secure Access gives organizations real-time visibility and control across traditional browsers such as Chrome, Safari, Firefox, and emerging AI browsers. By embedding protection directly into the browser runtime, it helps security teams enforce policy across browser sessions, applications, data movement, extensions, AI tools, and remote access workflows without forcing users into unfamiliar browsers or disruptive infrastructure changes. Falcon Secure Access enables users to securely continue working with the browsers and workflows they already know.
Our approach helps organizations:
- Secure access to SaaS, web, and internal applications without VPN or VDI friction
- Protect against phishing, malicious JavaScript, browser exploits, and session hijacking inside active sessions
- Continuously evaluate identity, device posture, user behavior, location, and threat context throughout the entire session
- Control data actions such as copy and paste, upload, download, screenshots, printing, and form entry
- Govern risky browser extensions, including AI-powered extensions
- Discover and control GenAI tool usage
- Enable secure access for contractors, third parties, bring your own device (BYOD) users, and unmanaged devices
- Reduce dependence on proxy infrastructure and remote isolation models that add cost and complexity
CrowdStrike is “redefining how enterprises secure digital interactions,” the report concluded, citing our engine-level approach, flexible deployment models, and ecosystem integrations as key reasons driving our leadership in the Zero Trust browser security market.
Built for the Distributed, AI-Powered Workforce
In addition to full-time employees using managed corporate devices, modern organizations often provision contractors, partners, consultants, suppliers, and third parties who require fast, secure access to enterprise resources from unmanaged or lightly managed devices.
Falcon Secure Access helps organizations enable these workflows with less friction. Instead of requiring VPN setup or forcing users into remote browser isolation, organizations can provide secure, separated work experiences that protect enterprise applications and data while helping preserve personal browsing privacy.
Secure access is no longer only about connecting a user to an application. It is about continuously protecting the full session after access is granted. Falcon Secure Access helps organizations apply real-time context-aware controls across identity, device posture, user behavior, browser activity, data movement, extensions, AI usage, and threat signals.
As AI accelerates the need for browser-native security, Falcon Secure Access delivers it. Employees are using GenAI applications, AI-powered browser extensions, AI-enabled SaaS features, and emerging agentic browsers to work faster and automate tasks. While these tools can increase productivity, they also create new risks around sensitive data exposure, prompt-based workflows, extension permissions, session access, and automated actions.
CrowdStrike secures how GenAI applications and agents are accessed through the browser, preventing shadow AI tools from scraping or exfiltrating sensitive data. Frost noted how the “ability to secure AI browsers and Electron apps (e.g., VS Code GPT integration) at the engine level addresses blind spots in traditional SASE/CASB models.”
Falcon Secure Access gives organizations granular visibility and policy enforcement across GenAI applications, AI-powered extensions, and emerging AI browser workflows. This helps teams adopt AI while maintaining control over sensitive data and enterprise access.
Extending the Falcon Platform into the Browser Session
Falcon Secure Access brings browser session telemetry and control into the broader Falcon platform. As part of CrowdStrike’s Continuous Identity vision, it extends real-time enforcement into the browser session, turning browser activity, user behavior, device posture, and application interaction into live signals for continuous access decisions.
As part of the Falcon platform, Falcon Secure Access extends CrowdStrike’s identity-first security, endpoint telemetry, threat intelligence, and AI-native detection into the browser. This brings browser activity into a broader security context across endpoint, identity, cloud, SaaS, threat intelligence, and data activity.
Frost & Sullivan noted the importance of Falcon Secure Access integrations with the Falcon platform, including CrowdStrike Falcon Zero Trust Assessment, CrowdStrike Falcon® Next-Gen SIEM telemetry, CrowdStrike Falcon® Shield for SaaS security posture management, CrowdStrike Falcon® AI Detection and Response (AIDR), and CrowdStrike Falcon® Next-Gen Identity Security to enforce zero standing privileges across human, non-human, and AI agent identities.
This creates a powerful path forward: Security teams can move beyond isolated browser tools and extend unified protection into one of the most important control points in the enterprise.
Learn more about CrowdStrike Falcon Secure Access by visiting the Falcon Secure Access webpage.
Read the report: Frost & Sullivan’s 2026 Global Enabling Technology Leader in Zero Trust Browser Security.
Join us in Las Vegas: Be part of Fal.Con 2026 and connect with 10,000+ cybersecurity professionals shaping the future of the industry.
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.