CrowdStrike unveils SafeMind AI security models with Nvidia at Fal.Con
CrowdStrike unveiled SafeMind, a security model family built with Nvidia, as AI attacks cut breakout time to seconds.
Kurtz said CrowdStrike created bespoke models for defenders, as well as an offensive model, to give customers choice. SafeMind is the first innovation from the CrowdStrike Cyber Superintelligence Lab, which the company describes as the first frontier AI research organization using AI to stay one step ahead of AI-based threats.
The urgency stems from shrinking attack timelines. theCUBE Research's Dave Vellante said Kurtz has used past Fal.Con keynotes to trace breakout time—the period from an initial foothold to movement toward another target—falling from two minutes to 72 seconds to 30 seconds. 'And now he's like, it's done. It's just runtime. There is no breakout time,' Vellante said in an analysis of the day-one keynote, according to SiliconANGLE.
CrowdStrike's '2026 Global Threat Report' reported an average eCrime breakout time of 29 minutes, while the fastest attack took only 27 seconds, according to Michael Sentonas, CrowdStrike's president. Sentonas said he had never seen an attack move so fast.
SafeMind consists of two models, Red Tempest and Blue Solano, trained on CrowdStrike incident data and built on Nvidia's Nemotron family, according to SiliconANGLE. Red Tempest hunts for attack paths by scanning a digital twin of the customer's environment, while Blue Solano writes rules to fix vulnerabilities and prevent or detect the simulated attack.
Nvidia Vice President and General Manager of Enterprise Computing Justin Boitano described the iterative process: 'The digital twin describes the environment of the actual world. You run the red agent through the environment and you'll find different ways in to exfiltrate data. Then the blue agent will come in and write rules that would have detected or prevented the red attack agent from getting through. That iterative loop basically hardens the environment.'
CrowdStrike Chief Business Officer Daniel Bernard said frontier models have brought AI innovation to the market, but that the benefit has also gone to adversaries. 'It's time for the defenders to have something, and it's time for security to have its own model,' he said. 'It turned into a set of models, a model family, and that's where SafeMind was born.'
CrowdStrike's research also points to a growing speed problem. Adam Meyers, senior vice president of intelligence, said the company tracked about 26 agentic adversaries in the last 30 days, more than it tracked in the prior year. Those AI-driven adversaries operate far faster than human attackers. Meyers cited VAULT PANDA, which conducted 1,100 commands in 58 minutes. 'It was an agent that was doing it, and we were watching it learn in real time,' he said.
Sentonas and Kurtz spoke with Vellante and host Rebecca Knight at Fal.Con during an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. The discussions included experts from Amazon, Nvidia, CISO Group and other organizations, focusing on how the best defense may be AI that goes on the offensive.