惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
MyScale Blog
MyScale Blog
博客园 - Franky
The Cloudflare Blog
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
WordPress大学
WordPress大学
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
腾讯CDC
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
博客园 - 【当耐特】
美团技术团队
云风的 BLOG
云风的 BLOG

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1 Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Simpler VPC Connectivity Control VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend VMware vSAN Protection and Recovery Enhancements for VCF 9.1 Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs
VMware and CrowdStrike Deliver New Integration for Cyber ...
belu de arbe · 2026-05-05 · via VMware Blogs

The digital landscape is evolving at a breakneck pace, but so are the threats within it. As organizations rush to integrate artificial intelligence (AI) into their operations, cyber adversaries are doing the same—with devastating efficiency. We are officially in the era of the “AI arms race”, where attackers use generative AI to automate reconnaissance, craft hyper-realistic phishing campaigns, and accelerate their path to your mission-critical data.

Today, the most common entry points remain classic yet lethal: phishing and stolen credentials. However, the nature of the attack has changed. According to the CrowdStrike 2026 Global Threat Report, we have entered the era of “logging in” rather than “breaking in.” A staggering 82% of interactive intrusions are now malware-free, as adversaries increasingly bypass technical defenses by exploiting stolen credentials and valid identities to blend in with legitimate network traffic. However, it’s what happens after the breach that is truly alarming. The concept of dwell time—where malware sits undetected, moving laterally to identify and infect sensitive applications—has been replaced by a “breakout” sprint. Once inside, attackers are moving faster than ever to encrypt data and compromise backups.

This shift has exposed a critical flaw in traditional defense: immutable and air-gapped backups and signature-based scans  are no longer enough. If an infection occurs and is replicated into your backups before detection, simply “restoring” means you are just re-infecting your environment. Traditional Disaster Recovery (DR) solutions are designed for power outages or natural disasters, not for the surgical precision needed to roll back through time, validate data, and find the exact “clean” restore point.

Beyond the Air-Gap: Why “Backing Up” is No Longer “Recovering”

In this high-velocity environment, the “clean room” has become the most important room in your data center. The industry is moving away from simple data restoration toward restore point validation. This process involves powering on workloads in a strictly isolated environment to run AI/ML-powered Endpoint Detection and Response (EDR) on the VMs before they ever touch your production site.

This is critical because of the rise of fileless attacks. These “living off the land” techniques are insidious; they don’t leave traditional signatures, making behavior-based analysis in an isolated clean room the only reliable way to detect them.

To survive, organizations must break down the silos between Infrastructure, Security, and Compliance teams. Security is no longer a “plugin” at the end of a project; it is the foundation of an integrated system of trust.

The release of VMware Advanced Cyber Compliance (ACC) 9.1 brings an integrated cyber recovery workflow to on-premises isolated clean rooms. This isn’t just a backup tool; it’s an end-to-end automation engine that spans identification, validation, and restoration at scale.

The Integrated Workflow Steps:

  1. Identify Recovery Point Candidates: Using Guided Restore Point Selection, IT teams can view a snapshot timeline enriched with metadata. By analyzing VMDK rates of change and file entropy (a key indicator, as encrypted data is highly randomized and harder to compress), teams can surgically select the most likely uninfected candidates for validation.
  2. Instant Power-On: Speed is the enemy of downtime. Recovery points are powered on instantly in the isolated clean room without the need for time-consuming data rehydration or VM format conversions.
  3. Restore Point Validation: This is where the magic happens. Through our collaboration, a CrowdStrike Falcon sensor is automatically injected into each VM in the clean room. It performs signature-based scanning, vulnerability analysis, and—most importantly—behavioral analysis to catch fileless threats. This happens in bulk, allowing you to iterate through snapshots until the “last known good” version is found. Best of all, customers can port their existing CrowdStrike licenses from their production site (which is likely down for forensics anyway) to the recovery site at no extra cost.
  4. Restore at Scale: Once the “clean” copies are verified and the production environment has been fortified, the workloads are failed back to production with confidence.

Resilience as the New Standard: The Path to Continuous Compliance

In today’s regulatory climate, cyber recovery is no longer just a “best practice”—it is a legal mandate. Regulatory bodies across the globe are demanding that organizations prove they can recover from a total systemic compromise, not just a hardware failure.

  • Financial Services: Frameworks like DORA (Digital Operational Resilience Act) in Europe and the SEC’s Cyber Disclosure rules in the Americas require rigorous stress-testing of recovery capabilities.
  • Healthcare: With HIPAA in the US and growing privacy mandates in the APAC region, protecting patient data requires a “last line of defense” that ensures clean restoration.
  • Federal Government: Recent White House Executive Orders (2026) emphasize the shift toward Zero Trust Architectures and AI-powered defenses to harden critical infrastructure.

By combining VMware’s hardened infrastructure and integrated cyber recovery with CrowdStrike’s industry-leading threat intelligence and EDR, we are providing more than just a product—we are providing a pioneering blueprint for cyber survival. Together, we are ensuring that when the next “27-second breakout” occurs, your organization has the tools to find the light, validate the truth, and recover with confidence.If you’d like to learn more, please visit the VMware Advanced Cyber Compliance website and the CrowdStrike website.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.