On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain. In collaboration with Google and the Shadowserver Foundation, we struck all four of Glassworm's command-and-control (C2) channels simultaneously, severing the operators from their infected machines and their ability to deliver new malicious payloads.
This takedown matters beyond the botnet. Glassworm marked a significant shift in the threat landscape that should serve as a wake-up call for every organization that ships or consumes software. Adversaries are no longer just targeting products, they're targeting the developers who build them.
https://t.co/rl9EVrA371
AI is accelerating cyber ops as China and DPRK-nexus actors evolve.
In a new CBS News interview, CrowdStrike’s @Adam_Cyber breaks down the threats facing financial institutions and what defenders need to know.
📺 https://t.co/0OrvJGgPEE
Day Zero: The 2026 Threat Research Summit is bringing together featured speakers from Amazon, Cisco, Google, Microsoft, Recorded Future, CrowdStrike, and more to share original research on emerging adversary tradecraft.
Applications are now open: https://t.co/LD6b7LFivO
Join us Aug. 30 – Sep. 1, 2026 in Las Vegas for a closed-door summit built for the cybersecurity community’s most technical minds — threat researchers, reverse engineers and intelligence experts working at the forefront of adversary analysis.
The lineup includes:
• Martin Wendiggensen, Dreadnode
• Ashley Shen, Cisco Talos
• Julian-Ferdinand Vögele, Recorded Future
• Selena Larson, Proofpoint
• A special session with John Hultquist, Google Threat Intelligence Group, and Sherrod DeGrippo, Microsoft
I’m excited to announce the inaugural CrowdStrike Day Zero 2026 Threat Research Summit, an invite-only event for researchers, defenders, and cost-imposing warriors on the front lines of cyber conflict.
Day Zero will showcase cutting-edge technical work, advanced research into adversaries and technology, and foster the kind of discussion that challenges assumptions and sharpens ideas.
CrowdStrike researchers are already submitting their ideas. The Call for Papers (CFP) is open, and these sessions will be closed-door, with strict information-sharing protocols in place.
Evening kickoff: Aug 30th | Day Zero 2026 Summit: Aug 31st
*Ahead of Fal.Con Vegas | 📍Mandalay Bay, Las Vegas
Register for updates and submit your paper.
https://t.co/28LUhtqEdn
Day Zero: The 2026 Threat Research Summit is bringing together featured speakers from Amazon, Cisco, Google, Microsoft, Recorded Future, CrowdStrike, and more to share original research on emerging adversary tradecraft.
Applications are now open: https://t.co/LD6b7LFivO
Join us Aug. 30 – Sep. 1, 2026 in Las Vegas for a closed-door summit built for the cybersecurity community’s most technical minds — threat researchers, reverse engineers and intelligence experts working at the forefront of adversary analysis.
The lineup includes:
• Martin Wendiggensen, Dreadnode
• Ashley Shen, Cisco Talos
• Julian-Ferdinand Vögele, Recorded Future
• Selena Larson, Proofpoint
• A special session with John Hultquist, Google Threat Intelligence Group, and Sherrod DeGrippo, Microsoft
Standardized on @Microsoft Defender but want the power of CrowdStrike's elite threat hunters? Now you can have both 🤝
Meet CrowdStrike Falcon OverWatch for Defender:https://t.co/oWZuGBc0IW
🔍 24/7 threat hunting focused on what automation misses
⚡ Real-time detection and response to sophisticated threats
👀 Deeper visibility without changing your existing deployment
You keep Defender. You gain a team hunting for the activity hiding in plain sight.
Disclaimer: Microsoft and Defender are registered trademarks of Microsoft Corporation. CrowdStrike is not affiliated with, endorsed, or sponsored by Microsoft.
🚀 Making history: CrowdStrike named a Leader in the inaugural @Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies!
📈 In the report, CrowdStrike is positioned furthest right for Completeness of Vision.
Learn more: https://t.co/jpf8njzumN
The latest Adversary Universe Podcast just dropped: Breaking Down the New National Cybersecurity Strategy
Adam & Cristian + special guest Rob Sheldon (Sr. Dir, Public Policy & Strategy @CrowdStrike) we cover:
• Offensive cyber ops push
• Updating legacy federal systems
• Protecting critical infrastructure
Real talk on threats & private sector impact.
Tune in: https://t.co/XIyY2OiTX8
#Cybersecurity #ThreatIntel
In conversations around the recent @CrowdStrike Global Threat Report the concept of eliminating cross domain visibility gaps in network hardware keeps coming up. What does this look like? How does it work?
This video showcases why it is essential to instrument edge devices and network appliance to hunt China nexus adversaries.
https://t.co/RWTWgpNBp7
Incredible work by CrowdStrike Counter Adversary Operations and our broader team on this year’s report.
The trend line is clear: breakout times continue to accelerate. Defenders have less time than ever to detect, respond, and contain before impact.
AI is reshaping the battlefield. Adversaries are operationalizing it to scale social engineering, reconnaissance, and development — while AI adoption across enterprises is simultaneously expanding the attack surface.
Cloud intrusions are rising sharply, with identity compromise remaining the dominant initial access vector. We’re also seeing an unprecedented number of nation-state actors targeting cloud environments.
China-aligned activity remains globally expansive, with increased focus on logistics and critical infrastructure. DPRK operations continue to blend espionage and revenue generation, including crypto theft.
The data is deep. The trends are clear. The implications are urgent.
A must read!
https://t.co/OCQT24ylsB
@crowdstrike is observing opportunistic eCrime actors l pushing Skrawl info stealer via fake OpenClaw skills on GitHub. One-line Terminal commands trick users into running it - steals Keychain, creds, crypto wallets.
See the blog we put out on open claw: https://t.co/0hXF7mXtaM
New from CrowdStrike: We’ve re-assessed LABYRINTH CHOLLIMA — now tracking it as three specialized DPRK adversaries
Read the blog: https://t.co/Qw62eCS97f
Plus, listen to the Adversary Universe Podcast breaking it down: https://t.co/3ngmg5GCCD
#ThreatIntel#DPRK#Cybersecurity
New reporting from CrowdStrike: WARP PANDA - This newly designated China-nexus adversary is deploying BRICKSTORM malware against vCenter servers and demonstrating deep familiarity with virtualized and cloud environments.
https://t.co/KSUrbyqIjC
Check out our latest blogpost analyzing political triggers intrinsic to deepseek. If you use deepseek and similar models for code development these loyal language models may increase vulnerable code to projects that are counter ccp ideology: https://t.co/82Jp2T37Lu
As we prepare to kick off Fal.con Europe, @CrowdStrike CAO is back with another threat landscape: https://t.co/UbMZtZB7GG
This report is packed with valuable insights into both the eCrime threat landscape and the activities of nation-state threat actors.
Launched the 2025 CrowdStrike APJ eCrime Report this morning in Singapore.
We’re tracking new eCrime groups from Vietnam and China, with major targeting across telecom, tech, and financials.
📖 https://t.co/aqGYZqaaqt
#CyberSecurity#eCrime#APJ#ThreatIntel