The $5 billion update error in CrowdStrike’s security software led to global disruptions, affecting airports, hospitals, and banking systems. This issue, caused by a faulty software update, resulted in Microsoft Windows computers experiencing "blue screen" failures, impacting approximately 8.5 million devices globally and requiring manual restarts. The malfunction halted aviation, disrupted healthcare services, and disabled some TV channels. Insurance company Parametrix estimated $5.4 billion in losses for 25% of affected Fortune 500 companies in the US and around $15 billion globally.
This paper examines the cybersecurity risks associated with vulnerabilities introduced by system updates, with a focus on critical infrastructures. To assess these risks, vulnerability scans were conducted across 12 critical infrastructure organizations, revealing an average 27% vulnerability rate related to updates. Through this study, we identify the evolving threat landscape and propose mitigation strategies to enhance cybersecurity posture, targeting a performance improvement of over 90%.
Primary Language | English |
---|---|
Subjects | Software Engineering (Other) |
Journal Section | Research Article |
Authors | |
Early Pub Date | January 13, 2025 |
Publication Date | |
Submission Date | October 9, 2024 |
Acceptance Date | November 13, 2024 |
Published in Issue | Year 2024 Volume: 14 Issue: 2 |
All articles published by EJT are licensed under the Creative Commons Attribution 4.0 International License. This permits anyone to copy, redistribute, remix, transmit and adapt the work provided the original work and source is appropriately cited.