{"slug": "four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal", "title": "Four insights you might have missed from theCUBE’s coverage of CrowdStrike’s Fal.Con", "summary": "CrowdStrike Holdings Inc. introduced SafeMind, a family of purpose-built security models built in partnership with Nvidia Corp., at its Fal.Con event, according to keynote remarks from founder, president and CEO George Kurtz. CrowdStrike's \"2026 Global Threat Report\" put average eCrime breakout time at 29 minutes, with the fastest attack taking 27 seconds, a figure cited by CrowdStrike President Michael Sentonas, who said, \"I've never seen anything move so fast.\" SafeMind is the first innovation from the CrowdStrike Cyber Superintelligence Lab, which the company describes as the first frontier AI research organization using AI to counter AI-based threats.", "body_md": "### Four insights you might have missed from theCUBE’s coverage of CrowdStrike’s Fal.Con\n\nAI-based cyberattacks are now able to infiltrate an organization in seconds, leaving security teams next to no time to defend against intrusion.\n\nThis risk and CrowdStrike Holdings Inc.’s vision for helping organizations fight back were the focus of keynote remarks at CrowdStrike’s [Fal.Con](https://siliconangle.com/tag/falcon26eventpage/) event by [George Kurtz](https://www.linkedin.com/in/georgekurtz) (pictured), president, chief executive officer and founder of CrowdStrike.  AI has dramatically reduced the time it takes an attacker to move from an initial foothold within an organization to another target, a measure known as “breakout time,” according to theCUBE Research’s [Dave Vellante](https://www.linkedin.com/in/dvellante/). \n\n“Every year at this conference, George steps up and says breakout time has gone from two minutes to 72 seconds, down to 30 seconds,” [Vellante said](https://siliconangle.com/2026/09/01/autonomous-red-teaming-crowdstrike-falcon/) in an analysis of the day one keynote. “And now he’s like, it’s done. It’s just runtime. There is no breakout time.” \n\nHere’s the complete Day 1 Keynote Analysis, part of SiliconANGLE’s and theCUBE’s coverage of [Fal.Con](https://siliconangle.com/2026/08/13/ai-attacks-crowdstrike-fal-con-thecube-falcon/): \n\n[CrowdStrike’s “2026 Global Threat Report”](https://www.crowdstrike.com/en-us/global-threat-report/) reported an average [eCrime breakout time](https://siliconangle.com/2026/09/01/ai-detection-response-emerges-security-category-falcon/) of just 29 minutes. The fastest attack took only 27 seconds , according to [Michael Sentonas](https://www.linkedin.com/in/michaelsentonas), president of CrowdStrike.\n\n“I’ve never seen anything like it. I’ve never seen anything move so fast,” he said. “That’s all happening on one side. On the other side … I think it’s fascinating. It’s so exciting. There’s so much possibility. There’s so much we can do. Unfortunately, the benefit we get is also the benefit the attacker gets. That’s kind of that challenge that we have right now.”\n\nAt Fal.Con, CrowdStrike introduced its solution to this problem: SafeMind, a family of purpose-built security models created in partnership with Nvidia Corp. SafeMind is the first innovation from the CrowdStrike Cyber Superintelligence Lab, which the company is positioning as the first frontier AI research organization that’s using AI to stay one step ahead of AI-based threats, Kurtz noted.\n\n“What we did is we created bespoke models that were built for defenders,” he said. “Oobviously we have an offensive model as well, which is needed. What we wanted to do was to give choice to customers.”\n\nHere’s the complete video interview with Michael Sentonas:\n\nSentonas and Kurtz spoke with Vallante and host [Rebecca Knight](https://www.linkedin.com/in/rebecca-m-knight-3667a94/) at [Fal.Con](https://siliconangle.com/tag/falcon26eventpage/), during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. Along with experts from Amazon Inc., Nvidia, CISO Group, and other organizations, they discussed how the best defense could be AI that goes on the offensive. *(* Disclosure below.)*\n\nHere are four key insights you may have missed from Fal.Con:\n\n### Insight #1: CrowdStrike bets on AI-powered red and blue teaming to harden defenses.\n\nSafeMind aims to give defenders access to the same advanced AI capabilities attackers are using. That need drove CrowdStrike to develop [security-specific models](https://siliconangle.com/2026/09/01/frontier-ai-gap-drives-crowdstrike-safemind-security-models-falcon/), explained [Daniel Bernard](https://www.linkedin.com/in/dblinkedin/), chief business officer of CrowdStrike.\n\n“Frontier models have done a fantastic job bringing AI innovation to the market at large. It’s really benefited the adversary,” he said. “It’s time for the defenders to have something, and it’s time for security to have its own model. It turned into a set of models, a model family, and that’s where SafeMind was born.”\n\nSafeMind consists of two AI models, [Red Tempest and Blue Solano](https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-launches-frontier-models-cybersecurity-created), trained on CrowdStrike incident data and built on Nvidia’s Nemotron family of AI models. Red Tempest hunts for attack paths by scanning a digital twin of the customer’s environment, explained [Justin Boitano](https://www.linkedin.com/in/justinboitano), vice president and general manager of enterprise computing at Nvidia. Blue Solano then fixes any vulnerabilities it finds.\n\n“The digital twin describes the environment of the actual world,” he said. “You run the red agent through the environment and you’ll find different ways in to exfiltrate data. Then the blue agent will come in and write rules that would have detected or prevented the red attack agent from getting through. That iterative loop basically hardens the environment.”\n\nHere’s the complete video interview with Daniel Bernard and Justin Boitano:\n\n### Insight #2: AI adversaries are shrinking the window to respond.\n\nCrowdStrike’s research shows that speed is becoming one of the biggest challenges for security teams facing [AI-driven threats](https://siliconangle.com/2026/09/03/agentic-adversaries-cut-attacker-intrusion-times-minutes-falcon/). Such threats have increased dramatically over the past year, according to [Adam Meyers](https://www.linkedin.com/in/adam-meyers-7a58481), senior vice president of intelligence at CrowdStrike. \n\n“The stat that’s most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days,” he said. “That’s more than we were tracking in the year before that.”\n\nThose agentic adversaries can move quickly. They operate far faster than human attackers, Meyers pointed out.\n\n“In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time,” he said. “When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I’m talking about an entire intrusion operation conducted in minutes from start to finish.”\n\nHere’s the complete video interview with Adam Meyers:\n\nBox Inc. uses CrowdStrike technology to help clients [prevent intruders](https://siliconangle.com/2026/09/01/agentic-ai-attack-surface-shifts-security-machine-speed-falcon/), including AI agents, from accessing sensitive corporate information. The technology strengthens protections for critical company data, according to [Heather Ceylan](https://www.linkedin.com/in/heatherceylan), Box’s chief information security officer. \n\n“Attack surface is the same, but it’s not just humans who are the attackers anymore,” she said. “It’s agents and they move at machine speed. So everything got faster. Our detections need to be faster, our visibility needs to be real time.”\n\nAI sprawl further complicates the problem. Enterprises have rushed to deploy bots across their businesses without necessarily building the architecture needed to govern access and trust, added [Cristian Rodriguez](https://www.linkedin.com/in/cristianr), field chief technology officer of the Americas at CrowdStrike.\n\n“They’re calling us saying, we have a problem, the AI sprawl is real, we know it’s in our SaaS apps, we know it’s on our endpoints, we know it’s in our cloud instances,” he said. “[They are saying] help us get our arms around visibility and governance programs and control, because we’ve bitten off a little more than we can chew.”\n\nHere’s the complete video interview with Cristian Rodriguez and Heather Ceylan:\n\n### Insight #3: AI is reshaping data loss prevention from the endpoint up.\n\nEndpoint security remains an [important focus](https://siliconangle.com/2026/08/31/device-ai-security-moves-below-os-pcs-falcon/) for security teams focused on enterprise data loss prevention. Implementing on-device AI security can help prevent data loss when, for example, an employee pastes sensitive corporate information into a chatbot, said [Todd Cramer](https://www.linkedin.com/in/todd-cramer-security), senior director of business development and security ecosystem at Intel Corp. \n\n“This year, we have Falcon data security from CrowdStrike announcing their first AI model that runs on an Intel NPU on a Dell device,” he said. “It’s the right time in the use case, because we’ve got all these AI assistants, chatbots. What’s the first thing CISOs are worried about? Data.”\n\nDell Technologies is developing hardware telemetry solutions that give security teams full visibility into threats. The technology provides coverage across the entire technology stack, said [Lori Zwilling](https://www.linkedin.com/in/lorizwilling), senior director of software product management at Dell Technologies Inc. \n\n“Not only are analysts seeing the endpoint behavior, but they also can see what’s happening with AI models, the data, the inferencing, the actual containers, the compute that’s powering the AI for the enterprise,” Zwilling said. “We’re talking about full-stack AI security now.”\n\nHere’s the complete video interview with Todd Cramer and Lori Zwilling:\n\nAI is also changing how DLP identifies risky data movement. Jazz Inc. won the 2026 Cybersecurity Startup Accelerator from CrowdStrike and Amazon Web Services Inc. for its [AI-based solution](https://siliconangle.com/2026/08/31/ai-powered-dlp-gets-second-act-jazz-crowdstrike-falcon/), which learns the business context surrounding risky outbound messages. AI-enabled DLP represents the evolution of a longstanding security challenge, according to [Ido Livneh](https://www.linkedin.com/in/ido-livneh), co-founder and chief executive officer of Jazz. \n\n“We didn’t build yet another pattern match or another rule-based system,” he said. “We completely upturned the whole challenge with our approach, which is building an investigator, a context-first, business-first investigator that understands your business, understands not only what is happening with the data flows, but why it’s happening, the intent, and solving it through that.”\n\nTraditional DLP tools have often struggled to prevent data loss at scale. AI could help address that limitation by analyzing large volumes of information more effectively, said [CJ Moses](https://www.linkedin.com/in/cjmoses/), chief information security officer and vice president of security engineering at Amazon.\n\n“In my experience, DLP providers have never done what DLP actually, the acronym, stands for. They’ve never done the data loss prevention,” he said. “With basically AI now being a thing that actually will allow you to be able to deal with the large scale of the information and how they’ve implemented was kind of game changing for us.”\n\nHere’s the complete video interview with CJ Moses, Ido Livneh, and Daniel Bernard:\n\n### Insight #4: An ecosystem strategy underpins CrowdStrike’s AI security push.\n\nCrowdStrike is positioning SafeMind as the first major achievement of its Cyber Superintelligence Lab. The lab is developing technology intended to automate routine security tasks at the speed required to counter modern adversaries, CrowdStrike CEO Kurtz [told theCUBE](https://siliconangle.com/2026/09/02/ai-control-plane-george-kurtz-safemind-falcon/).\n\n“Part of why we started the Cyber Superintelligence Lab is to be able to build these sort[s] of technologies so that we can get to a level of automation where the car drives itself,” he said. “Maybe the human has to be in the loop, and if something’s really critical, fine. If you can automate the most mundane task and you can do it with the speed at which the adversary is moving, that’s going to be critical.”\n\nHere’s the complete video interview with George Kurtz:\n\nThe lab’s goal is to “disproportionately bias the advantage towards the defender,” according to [Bartley Richardson](https://www.linkedin.com/in/bartleyrichardson), chief AI and autonomous systems officer at CrowdStrike.\n\n“The real remit of the lab is the commoditization of defense capabilities. It is [turning] the best offense into that disproportionately advantaged defender-like capability,” [Richardson told theCUBE](https://siliconangle.com/2026/09/02/cyber-superintelligence-lab-aims-tilt-ai-edge-defenders-falcon/). “How are we improving other areas in the industry itself? What can we contribute back?” \n\nHere’s the complete video interview with Bartley Richardson:\n\nPartnerships will also be key, as evidenced by CrowdStrike’s Project QuiltWorks, a cross-industry alliance of technology companies, law firms, consultancies, and others focused on finding and fixing security vulnerabilities surfaced by AI models.\n\n“QuiltWorks is a coalition of folks and partners who join us; they leverage our platform,” explained [Amanda Adams](https://www.linkedin.com/in/amandapielstick), senior vice president of global alliances at CrowdStrike, [in an interview with theCUBE](https://siliconangle.com/2026/09/02/aws-crowdstrike-partnership-takes-agentic-ai-threats-falcon/). “We announced yesterday [Falcon IQ](https://siliconangle.com/2026/08/31/crowdstrike-launches-falcon-iq-as-falcon-lands-on-google-cloud-and-snowflake/), and this is a tool built on AWS that allows a partner to essentially drive an assessment and highlight the opportunities, the priorities. It’s using AI to accelerate the time from discovery to remediation down to minutes.” \n\nCrowdStrike’s partnership with Amazon Web Services has also evolved alongside the technology, according to [Mona Chadha](https://www.linkedin.com/in/mona-chadha-6a32b610/), director, strategic partnerships and category growth at Amazon Web Services Inc.\n\n“Over the decade, what we continued to do was build innovations together,” [Chadha told theCUBE](https://siliconangle.com/2026/09/02/aws-crowdstrike-partnership-takes-agentic-ai-threats-falcon/). “We’ve evolved from machine learning to generative AI to now agentic and building these agents. There’s a lot of opportunity there, but there [are] also a lot of threats.”\n\nHere’s the complete video interview with Mona Chadha and Amanda Adams:\n\nCatch up on our [complete video coverage](https://www.youtube.com/playlist?list=PLK5JkEj2_qlo) of Fal.Con: \n\n*(* Disclosure: TheCUBE is a paid media partner for Fal.Con. Neither CrowdStrike, the headline sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)*\n\n##### Photo: SiliconANGLE\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n- **15M+ viewers of theCUBE videos** , powering conversations across AI, cloud, cybersecurity and more\n- **11.4k+ theCUBE alumni** — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network\n\n### Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: [https://siliconangle.com/aws-marketplace/](https://siliconangle.com/aws-marketplace/)\n\n##### **About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal", "canonical_source": "https://siliconangle.com/2026/09/15/four-insights-ai-based-cyberattacks-crowdstrikes-falcon/", "published_at": "2026-09-15 21:59:25+00:00", "updated_at": "2026-09-15 22:05:43.391427+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-products", "ai-research"], "entities": ["CrowdStrike Holdings Inc.", "SafeMind", "Nvidia Corp.", "George Kurtz", "Michael Sentonas", "CrowdStrike Cyber Superintelligence Lab", "Fal.Con", "Daniel Bernard"], "alternates": {"html": "https://wpnews.pro/news/four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal", "markdown": "https://wpnews.pro/news/four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal.md", "text": "https://wpnews.pro/news/four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal.txt", "jsonld": "https://wpnews.pro/news/four-insights-you-might-have-missed-from-thecubes-coverage-of-crowdstrikes-fal.jsonld"}}