The update that crashed millions of Windows machines on July 19, 2024 wasn't a hack. It listed 21 fields where the system expected 20.
That one extra field was enough. The crash hit so early in startup that the machines couldn't restart to take a fix, so recovery meant repairing each one by hand in Safe Mode.
And nobody was standing between the vendor and those machines to check the update on the way in. The vendor validates its own work, everyone downstream trusts it, and no independent layer read the actual file before it reached a single endpoint.
So we built a demo, Kestrel, to be that missing layer. It replays that same update against a stand-in fleet of 8,500 machines and blocks it before one of them reboots. The verdict isn't set by the AI. An AI crew argues both sides, then plain code re-checks the arithmetic: 21 fields where 20 were expected, so it refuses the rollout.
(The fleet and the vendor are both synthetic, replaying the documented CrowdStrike failure without a real outage.)
It isn't a block-everything nanny, either. A harmless update from the same vendor passes straight through to a small first wave in seconds.
If you run a large fleet, one question to answer honestly: how many vendor agents on your machines can push an update straight into the kernel, with no one outside that vendor checking it first? For most teams it runs higher than expected.
#EndpointSecurity #ITResilience #CyberResilience #CISO
Published on Facebook · September 11, 2026
On social media
See this post on its original platform
In our archive