The White House and the U.S. Government Accountability Office (GAO) are raising alarms about the robustness of the software supply chain and vulnerabilities related to memory safety.
Federal authorities pointed out that a recent global IT outage, caused by a defective CrowdStrike software update, has reignited longstanding concerns about software supply chain security.
In a report released on Tuesday, the GAO highlighted the July 19 incident, which disrupted 8.5 million Microsoft Windows systems. This event has rekindled issues reminiscent of the state-sponsored supply chain attack on SolarWinds in 2020.
The White House underscored the significance of this outage in relation to memory safety warnings in software development. Building on a February report, officials emphasized the connection between memory safety issues and software vulnerabilities.
A spokesperson for the Office of the National Cyber Director (ONCD) told Cybersecurity Dive via email on Thursday that ONCD is actively tackling the complex challenge of national cybersecurity. As part of the National Cybersecurity Strategy, the office continues to focus on addressing memory safety vulnerabilities.
In February, ONCD released a report urging the tech industry to adopt memory-safe programming languages and chip architectures. The report also called on the research community to enhance the tools for diagnosing and measuring software security.
Companies such as SAP, Palantir, and Hewlett Packard Enterprise have supported the administration’s initiative to promote memory-safe coding practices.
Microsoft and CrowdStrike are conducting thorough reviews of the outage to determine preventive measures and mitigate future incidents. Microsoft confirmed that the faulty software update in the CrowdStrike Falcon platform was linked to a read-out-of-bounds memory safety error in the CSagent.sys driver, as noted in a Saturday blog post.
CrowdStrike stated that a rapid response update was deployed on July 19 to collect additional data on new adversary techniques. This update, applied to Windows hosts with sensor version 7.11 and above, contained problematic content that caused affected systems to crash due to an out-of-bounds memory read.
The Cybersecurity and Infrastructure Security Agency (CISA) is collaborating with government and industry partners to assess the IT outage’s impact and provide further support.



