Welcome home, fellow Gator.

The Gator Nation's oldest and most active insider community
Join today!

Planes Grounded, Businesses Disrupted Due to Tech Issue

Discussion in 'Too Hot for Swamp Gas' started by citygator, Jul 19, 2024.

  1. citygator

    citygator VIP Member

    10,407
    2,316
    3,303
    Apr 3, 2007
    Charlotte
    Crowdstrike security software had an update issue that took down many businesses globally. Supposedly fixed and cascading to businesses.

    I have coworkers stuck at airports and most of my company's systems didnt update last night. Going to be a pain if you are traveling. Saw a report 1/3 of McDonald's in Japan were closed due to register issues.

    Is this a test run for Skynet?

    Live updates: Microsoft global outage hits airlines, banks and businesses | CNN Business

     
    • Informative Informative x 1
  2. tilly

    tilly Superhero Mod. Fast witted. Bulletproof posts. Moderator VIP Member

    Alaska's 911 service is/was down.
    ESPN was unable to air live programs (SportsCenter was not aired this AM.)
    Airports worldwide could not scan passengers.
    Reports of surgeries being cancelled and patient records not loading.

    My phone was blowing up before I got to the office asking for us to check all systems. Oddly, my office laptop had updated overnight and had to be restarted which made me nervous.

    What a mess.
     
    • Fistbump/Thanks! Fistbump/Thanks! x 1
  3. GCNumber7

    GCNumber7 VIP Member

    5,660
    380
    518
    Apr 3, 2007
    Someone really f’ed up an update.
     
    • Fistbump/Thanks! Fistbump/Thanks! x 1
    • Funny Funny x 1
    • Optimistic Optimistic x 1
  4. 92gator

    92gator GC Hall of Fame

    13,856
    14,253
    3,363
    Jun 14, 2007
    The Russians?

    Terrorists?

    Chicoms?

    ...or is it really just a human error @#%$ up?

    :ninja3:
     
  5. citygator

    citygator VIP Member

    10,407
    2,316
    3,303
    Apr 3, 2007
    Charlotte
    Rumor is an FSU intern. :)
     
    • Funny Funny x 8
    • Informative Informative x 1
  6. ATLGATORFAN

    ATLGATORFAN Premium Member

    3,340
    867
    2,153
    Aug 10, 2015
    hard to believe this was the result of poor code in a single crowdstrike/microsoft update.
     
    • Agree Agree x 2
  7. GCNumber7

    GCNumber7 VIP Member

    5,660
    380
    518
    Apr 3, 2007
    Have not seen an RCA yet, but Crowdstrike already put out a fix and rebooting affected windows instances ‘should’ fix the issue.
     
  8. antny1

    antny1 GC Hall of Fame

    4,686
    2,434
    2,498
    Dec 3, 2019
    Affected 911 here in volusia. Computers down. Also my bank log in is fine but investment firm website is down
     
  9. citygator

    citygator VIP Member

    10,407
    2,316
    3,303
    Apr 3, 2007
    Charlotte
    Simple instructions as to how to fix from someone I am friends with that their company sent out o_O. She is a non-tech HR person. I mean, I cant even.

    1. Cycle through your blue screens until you get the recovery screen.
    2. Navigate to "Troubleshoot>Advanced Options>Startup Settings
    3. Press "Restart"
    4. Skip the first Bitlocker recovery key prompt by pressing Esc
    5. Skip the second Bitlocker recovery key prompt by selecting Skip This Drive in the bottom right
    6. Navigate to Troubleshoot>Advanced Options>Command Prompt
    7. Type bcdedit /set {default} safeboot minimal
    8. Hit enter
    9. Go back to the WinRE main menu and select Continue
    9. It may cycle 2 to 3 times
    10. If you booted in safe mode, log in as normal
    11. Open Windows Explorer, navigate to C:\Windows\Systen32\drivers\Crowdstrike
    12. Delete the offending file (STARTS with C-00000*.sys file extension)
    13. Open command prompt (as administrator)
    14. Type bcsedit /deletevalue {default} safeboot
    15. Press enter
    16. Restart as normal, confirm normal behavior
     
    • Informative Informative x 1
  10. vaxcardinal

    vaxcardinal GC Hall of Fame

    6,847
    1,031
    2,043
    Apr 8, 2007
    thanks Brandon
     
    • Funny Funny x 2
  11. ValdostaGatorFan

    ValdostaGatorFan GC Hall of Fame

    2,649
    532
    1,998
    Aug 21, 2007
    TitleTown, USA
    IT guy here... They done goofed. It sounds like this hasn't been automated yet and every device will need to be touched. Yikes.
     
    • Informative Informative x 1
  12. tilly

    tilly Superhero Mod. Fast witted. Bulletproof posts. Moderator VIP Member

    Nah. Commodore 64's were unaffected.
     
    • Funny Funny x 1
  13. tilly

    tilly Superhero Mod. Fast witted. Bulletproof posts. Moderator VIP Member

    Nope. Before I do ALL that I am telling IT that I spilled my coffee and to send me a new laptop. :D
     
    • Like Like x 2
  14. GCNumber7

    GCNumber7 VIP Member

    5,660
    380
    518
    Apr 3, 2007
    CEO getting hammered for his non-apology.

     
    • Dislike Dislike x 1
  15. GatorFanCF

    GatorFanCF Premium Member

    4,891
    936
    1,968
    Apr 14, 2007
    Thanks to ValdostaGatorFan for the IT perspective. From a Risk perspective this is one reason to have Cyber insurance as it can be written (but is not always) to cover "dependent business interruption" - in essence, paying for your loss of income due to a connected party of yours having an issue. Stay safe out there and don't fall for the urgent need from "your CFO" demanding a wire be sent while he/she is about to go on vacation. Thieves are clever.
     
    • Fistbump/Thanks! Fistbump/Thanks! x 1
  16. ValdostaGatorFan

    ValdostaGatorFan GC Hall of Fame

    2,649
    532
    1,998
    Aug 21, 2007
    TitleTown, USA
    A part of a risk assessment, or insurance in general, should include regular in-house and 3rd part pentesting. A lax security posture should lead to a company being un-insurable. Sadly, in this case, companies were using Crowdstrike, which is good, but Crowdstrike really mucked up. Similar to the SolarWinds Orion supply chain attack, sometimes even doing the right thing ends poorly.
     
  17. ValdostaGatorFan

    ValdostaGatorFan GC Hall of Fame

    2,649
    532
    1,998
    Aug 21, 2007
    TitleTown, USA
    240544.jpeg
     
    • Funny Funny x 9
  18. G8trGr8t

    G8trGr8t Premium Member

    30,475
    11,745
    3,693
    Aug 26, 2008
    or that is the story and an official actor f'd us up on purpose. hide in the crowdstrike update and then deploy once rooted in?

    crowdstrike has made lots of enemies and I assume their talent pool isn't squeeky clean...???
     
    • Like Like x 1
  19. ValdostaGatorFan

    ValdostaGatorFan GC Hall of Fame

    2,649
    532
    1,998
    Aug 21, 2007
    TitleTown, USA
    That was the mechanism of the SolarWinds hack. Supply chain attack.

    I have a hard time believing that it wasn't thoroughly tested before deployed, but ish happens. IMO, if a nefarious actor inserted code into the update before it was deployed, they'd do a lot more damage than some bluescreens. Time will tell, though.

    I just got a call from my coworker, also IT, and he's stuck in the ATL airport. He called me after seeing several BSODs and recovery screens. Yikes. Another co-worker, non IT, is stuck in Wisconsin because of issues at an airport there.
     
  20. LimeyGator

    LimeyGator Official Brexit Reporter!

    This is how I'd have solved it:

    [​IMG]
     
    • Funny Funny x 3