CrowdStrike hires outside help to track down cause of global power outage after releasing initial findings

As CrowdStrike and its enterprise customers recover from the recent power outage disasterand it is already common knowledge that a pushed update caused the problemthe company has hired two security firms to further investigate the matter.

The external code review was announced in a root cause analysis (PDF), while this was already known in the course of a post incident evaluation that a system designed to validate content (a “Content Validator”) failed, allowing a faulty IPS Template Instance intended to detect attacks to validate anyway, causing crashes due to out-of-bounds memory reads.