Site Search

CrowdStrike

CrowdStrike

CrowdStrike June 2025 Update

We are pleased to present the CrowdStrike update information for June 2025.
All of these issues have been posted on our support site, so please check those articles as well.

Registration is required for our support site.

Please click on "CrowdStrike Falcon 'Support Site Viewing Request'" on the following page to request viewing.
https://www.macnica.co.jp/business/security/manufacturers/crowdstrike/support.html

*The maintenance contract number is required for application. The maintenance contract number is listed in the notification sent to you with the subject below.
Subject: [Notice regarding delivery of CrowdStrike notification]

* Responses usually take 1 to 3 business days.

Sensor Release

Falcon Sensor for Windows 7.26.19809 Release Announcement [Released 2025/06/17]

  • Main fixes
    • For Falcon sensor for Windows versions 7.23 and later, we have updated the on-sensor machine learning (ML) model to resolve the reported false positives.
    • Falcon Prevent: Fixed a rare issue where a scan would detect malicious files but not report details.
    • An issue where certain files and folders were scanned even though the exclusion pattern correctly started with the root drive (directory) has been fixed.
    • Falcon Firewall Management: Fixed an issue where the rule version was being reported incorrectly for some logged traffic.
    • The local IP address enumeration interval has been changed from 3 days to 30 minutes to provide quicker visibility.
    • Falcon Data Protection: Fixed a bug in the data upload restriction policy in Incognito/InPrivate browsers, allowing sensors to work in certain versions of Chrome and Edge.

Falcon Sensor for Linux 7.26.17905 Release Announcement [Released 2025/06/17]

  • Main New Features
    • Linux kernels earlier than 6.14.x are now supported in User mode.
    • Falcon Prevent: A new prevention policy, “D-Bus Visibility,” has been added to provide greater visibility into D-Bus messages.
      ・Detailed article: https://support.mnc.macnica.co.jp/hc/ja/articles/48240913828377
    • The DaemonSet container has been updated to use Red Hat Universal Base Image (UBI) 9.5.
    • User mode support has been added for RHEL 10 and related kernels (Alma Linux, Oracle RHCK, Rocky Linux).
  • Main changes
    • A compatibility issue caused by Google's OS Login NSS module has been resolved, and local user and group management visibility has been restored in user mode.
    • Resolved an issue where sensors went into reduced functionality mode on custom kernels with CONFIG_IA32_EMULATION disabled.
  • Kernel Support
    • Support has been added for new kernels, including previously unsupported versions of Amazon Linux, Debian, Oracle Linux, Red Hat Enterprise Linux, and Ubuntu.

Falcon Sensor for Mac 7.25.19607 Hotfix Release Announcement [Released 2025/06/03]

  • Main changes
  • We fixed the cause of an internally discovered "mach port leak" issue that occurred in sensor version 7.25.19606. This issue occurs when the number of ports opened by the Falcon sensor's "Agent" process gradually increases until the system reaches the maximum number of ports configured, causing the sensor to automatically restart. This issue is estimated to occur approximately once every 40 days on a typical Mac host, has no impact on the host OS, and the sensor resumes detection and protection within seconds.

Release Announcement

Regular updates to the Admin Console

  • CrowdStrike Falcon Console Regular Updates [As of the week of May 26, 2025]
    • New Features
      Foundry: You can now upload and embed images into Foundry app README documents, enhancing structure, style, and organization of your documentation.
      Fusion SOAR: The Zero Trust Assessment workflow has been expanded to incorporate platform-agnostic triggers and conditions, including for mobile hosts.
      Fusion SOAR: You can now set workflow conditions based on failed OS evaluations for Android and iOS.
      Falcon Complete Next-Gen MDR: Added support for new data sources for Next-Gen SIEM.
      Endpoint detections: You can now group endpoint detections based on process trees and other detection attributes.
  • CrowdStrike Falcon Console Regular Updates [As of the week of June 2, 2025]
  • CrowdStrike Falcon Console Regular Updates [As of the week of June 9, 2025]
    • New Features
      Falcon Foundry: The Foundry CLI, a command line tool that helps with app development and management, has been upgraded to version 1.4.2.
    • Fixes
      Falcon Foundry: Fixed an issue when syncing apps using the Foundry CLI on Windows.
    • Please see our support site article for more information.
      https://support.mnc.macnica.co.jp/hc/ja/articles/48009733556377
  • CrowdStrike Falcon Console Regular Updates [As of the week of June 16, 2025]
    • New Features
      Falcon Complete Next-Gen MDR: Next-Gen SIEM now supports new data sources including GitHub Enterprise and Microsoft Azure DevOps.
      Falcon Forensics: Server Name Indication (SNI) now matches Falcon Forensics cloud endpoints, improving compatibility with network security appliances.
    • Please see our support site article for more information.
      https://support.mnc.macnica.co.jp/hc/ja/articles/48219433841049

Other Updates

  • Announcement of new Host Groups screen release
    • The Host Groups screen has been redesigned to have a more consistent layout with other CrowdStrike Falcon Console screens.
    • This brings several usability improvements, such as making it easier to view related host groups and change policy assignments.
      https://support.mnc.macnica.co.jp/hc/ja/articles/47704638342937
  • Vulnerability detection expanded for RHEL EUS and RHEL SAP
  • Falcon Sensor for Windows/Mac | New feature added (Sensor Safe Mode)
    • Falcon Sensor for Windows version 7.26 and Falcon Sensor for Mac version 7.26 introduce a new feature called Sensor Safe Mode that will detect when your system is in a sensor-related boot loop or experiencing repeated crashes and take corrective action.
      https://support.mnc.macnica.co.jp/hc/ja/articles/48036383251481

Module-specific updates

  • Falcon Identity Protection
    • Falcon Identity Protection 5.92.75905 Release Announcement [Released 2025/06/03]
      Many new features have been added, including improved abnormal behavior verification, Active Directory management, and dashboard visualization. In addition, various detection and integration issues have been fixed, providing more stable security management.
      -https://support.mnc.macnica.co.jp/hc/ja/articles/47650932212505
  • Falcon Data Protection
    • Fine-grained access to control visibility into Falcon Data Protection events
      Fine-grained access (FGA) now gives Falcon Administrators granular control over what user access is granted to specific hosts, beyond standard CID-level permissions.
      *This control only applies to Data Protection events and not to detections.
      -https://support.mnc.macnica.co.jp/hc/ja/articles/47890282818329
  • NG-SIEM
    • Falcon Next-Gen SIEM Recently Released Features/Fixes/Known Issues [June 2025 Update]
      Many new features have been introduced, including the ability to customize detection IDs, integration of detections based on process trees, and the addition of new security roles for MSSP. In addition, some issues related to log management have been fixed.
      -https://support.mnc.macnica.co.jp/hc/ja/articles/47928005664025

Notes and Restrictions

  • [IMPORTANT] 300 Days Notice | March 2026 | Falcon Cloud SSL Certificate Renewal
    • The Falcon Cloud SSL certificates for US-1, US-2, EU-1, and US-GOV-1 will be rotated on March 16, 2026. This means that certain Falcon sensor versions will no longer be able to connect to the US-1, US-2, EU-1, and US-GOV-1 Falcon Cloud after 23:00 (UTC) on March 16, 2026. Therefore, you must update your Falcon sensor to a specific version or later by March 16, 2026. Please check our support site for version information.
      https://support.mnc.macnica.co.jp/hc/ja/articles/46936900847897
  • 180 Days Notice | Falcon Complete Dashboard API Endpoint Deprecation [Scheduled for Deprecation on December 2, 2025]

Maintenance and fault information

Inquiry/Document request

In charge of Macnica CrowdStrike Co., Ltd.

Weekdays: 9:00-17:00