
Microsoft said on Saturday (July 20) that the global tech outagethat was related to a software update by cybersecurity firm CrowdStrike affected nearly 8.5 millionMicrosoftdevices. In a blog post, Microsoft said, "We currently estimate that CrowdStrike's update affected 8.5 million Windows devices or less than one per cent of all Windows machines."
"While the percentage was small, the broad economic and societal impacts reflect the use of CrowdStrike by enterprises that run many critical services," the American software giant added.
A software update by global cybersecurity firm CrowdStriketriggered systems problems across the world that grounded flights, forced broadcasters offair, and left customers without access to services such as healthcare and banking.
Also read |Australia warns of scams post cyber outage
Problems came to light quickly after the update was rolled out on Friday, and users posted pictures on social media of computers with blue screens displaying error messages.
According to security experts, CrowdStrike's update which caused the global outagedid not undergo adequate quality checks before it was deployed.
A report by the news agency Reuters said that the latest version ofits Falcon sensor software was meant to make CrowdStrike clients' systems more secure against hacking by updating the threats it defends against.
However, a faulty code in the update filescaused the outage.
Also watch |Gravitas: Microsoft outage disrupts flights, banks, and media outlets around the world
CrowdStrike released information to fix affected systems, but experts said getting them back online would take time as it required manually weeding out the flawed code.
Problems came to light quickly after the update was rolled out on Friday. Users posted pictures on social media of computers with blue screens displaying error messages.
Security researcher Patrick Wardle said that his analysis identified the code responsible for the outage. Wardle said that the update's problem was in a file that containedeither configuration information or signatures.
Such signatures are code that detectspecific types of malicious code or malware.
"It's very common that security products update their signatures, like once a day... because they're continually monitoring for new malware and because they want to make sure that their customers are protected from the latest threats," he said.
The frequency of updates was probably the reason CrowdStrikedidn't test it as much, he added.
(With inputs from agencies)