JUCS - Journal of Universal Computer Science 32(7): 1016-1030, doi: 10.3897/jucs.161865
CrowdStrike Blackout: Impacts, Technical Root Causes, and Lessons Learned from a Multivocal Analysis of a Critical Incident
expand article infoVinicius Eduardo Ferreira, João Pedro Vidotti Cesaro, Gabriela Rosa, Edson OliveiraJr, Gislaine Camila Lapasini Leal, Renato Balancieri
‡ State University of Maringá, Maringá, Brazil
Open Access
Abstract
 In July 2024, a failed update in the CrowdStrike Falcon security software disrupted critical services across the United States and several other countries, affecting sectors such as aviation, healthcare, and finance. Despite advancements in automated testing, an error introduced during development was rapidly propagated, exposing vulnerabilities in digital infrastructure and underscoring the risks of technological interdependence. This study examines the incident through an integrative, multivocal literature review that combines academic and gray literature to address three core research questions: the impacts of the outage (RQ1), the technical causes of its severity (RQ2), and the lessons learned for software engineering and cybersecurity (RQ3). The analysis reveals critical failures in validation processes, integration mechanisms, and organizational prac-tices, highlighting the need for robust quality assurance and software governance. The findings contribute to both research and practice by informing more effective strategies for preventing and responding to large-scale cybersecurity incidents.
Keywords
Cybersecurity Incident, CrowdStrike Falcon, Multivocal Literature Review
login to comment