U.S. cybersecurity agency CISA has acknowledged that while the CrowdStrike outage is *not* a cyberattack, it has observed malicious actors "taking advantage" of the s(h)ituation for "phishing and other malicious activity" and warned organizations to "avoid clicking on phishing emails or suspicious links."

More: https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update

@zackwhittaker btw unless/until we know what happened to the update at crowdstrike this could theoretically still be a supply chain attack.
@zackwhittaker „avoid clicking on phishing emails or suspicious links“ sounds so easy. Wish it was^^
@zackwhittaker Let's be clear, it's an attack. Friendly fire is still fire

@ricci

"It wasn't a terrorist that took the bridge down, it just so happens that a highly respected company was storing dynamite and blasting caps under a huge pile of oily rags."

Intent doesn't change the outcome. And I can't believe this is the result of anything less than criminally gross negligence.

@zackwhittaker