>

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach's Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself

CrowdStrike’s Falcon Outage: 8.5M Windows Hosts and the Architecture of Fragility

On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.

Continue ReadingCrowdStrike’s Falcon Outage: 8.5M Windows Hosts and the Architecture of Fragility
>