Fun fact: when I worked in security I used to install and maintain Crowdstrike agents (among other security vendor products) on customer machines. It's not Windows-only, they also have a Linux client. Which runs as a kernel module and requires auditd.

They also have a mac client, though it looks like neither Linux nor Apple machines were affected by the bad update.

I'd view that as pure dumb luck until I actually see an RCA. Because of the way their agents work, any system could be utterly borked.

I would have thought at Crowdstrike's scale that SURELY they use a slow-rollout/canary model for global updates. But the scale of this outage suggests otherwise. There's no way the rollout should have continued with 100% of clients not checking in.
I'm rolling my eyes at the people going off about "don't deploy on Fridays". This went out Thursday night. No matter what day of the week it went out, it's going to take more than a work week to fix and everyone's weekend would be toast. Sometimes you just ship real stinkers, lol
Everyone loves to confidently proclaim that companies shouldn't do X or Y (don't use rootkits for security! audit checkboxes are useless!) but it's funny how there's always dead silence when you ask what companies who really don't have security as a core competency should do instead
@ehashman cloud native companies are _head and shoulders_ above anybody still doing on prem anything. Let Googleโ€™s security team do pager duty for your login form
@ehashman at least judging by my clients (people can also hire me, I mean)