Nvidia and CrowdStrike have unveiled SafeMind, an agentic cybersecurity system built by CrowdStrike's Cyber Superintelligence Lab that pairs CrowdStrike's own frontier-capable models with defensive models built on Nvidia's Nemotron open-model family.

The system was announced by Nvidia founder and chief executive Jensen Huang and CrowdStrike chief executive George Kurtz at CrowdStrike's Fal.Con 2026 conference in Las Vegas on Tuesday, addressing a crowd of 10,000 security professionals. Huang said escalating automated attacks meant defence needed to become similarly automated, describing the launch as the start of "a new age of cybersecurity".

SafeMind runs natively in CrowdStrike's Falcon platform, using Nvidia Nemotron 3 Ultra to orchestrate its defensive agent harness and a fine-tuned Nemotron 3 Super to power its rule-generation sub-agent. CrowdStrike said internal testing showed its Nemotron-based Blue Solano model delivered higher accuracy rates than leading frontier models at 99% lower cost.

The system operates a continuous "coevolution loop" in which offensive and defensive AI agents repeatedly challenge and adapt to one another, a process CrowdStrike said progressively hardens customer environments against attack. Nvidia tested the approach in a simulated digital twin of its own accelerated computing infrastructure, running red-team sub-agents named Recon, Assault and Compromise against a blue-team harness that monitors, generates, validates and promotes detections via CrowdStrike's Falcon sensors.

CrowdStrike also announced Falcon IQ, which operationalises what the company calls Project QuiltWorks and uses more than 50 coordinated agents to automate security assessment, prioritisation and remediation work. Falcon IQ runs within Charlotte AI AgentWorks, CrowdStrike's no-code platform allowing customers to build their own agentic security workforce, and the company said it has also expanded its Guardian AI safety solution.

According to CrowdStrike, AI-enabled attacks rose 89% over the past year, with the fastest recorded breach time reaching 27 seconds.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!