Quick Facts

  • CrowdStrike introduced SafeMind, a family of offensive and defensive AI security models, at Fal.Con 2026, with CoreWeave supplying training and inference infrastructure.
  • CrowdStrike's 2026 Global Threat Report recorded a fastest-ever eCrime breakout time of 27 seconds and an 89% increase in attacks by AI-enabled adversaries.
  • CrowdStrike's internal evaluations claim SafeMind delivers a 29% higher detection rate, six times faster remediation, and 99% lower costs compared with frontier models and open-source baselines.

CrowdStrike and CoreWeave are deepening a global partnership to secure AI workloads and defend enterprise networks against threats moving faster than any human operator can respond. The two companies made joint announcements at Fully Connected, CoreWeave's AI cloud conference, which drew more than 4,500 customers, partners, and developers.

The centerpiece of the announcement is CrowdStrike SafeMind, a family of purpose-built security models developed inside CrowdStrike's Cyber Superintelligence Lab. SafeMind runs natively within the CrowdStrike Falcon platform. It is not a single model but a system of two models operating inside harnesses that pit them against each other continuously.

The offensive model, called Red Tempest, is built for advanced attack scenarios and emulates AI adversaries. The defensive model, called Blue Solano, deploys countermeasures to protect enterprise assets. The two models run in the same loop, learning from each attack cycle to sharpen detection and remediation over time.

CoreWeave supplies training and inference capacity for SafeMind and serves as a design partner for the Cyber Superintelligence Lab. The models are trained using CrowdStrike Falcon telemetry, threat intelligence, Falcon Complete MDR annotations, and 15 years of incident-response data.

"The name of the game is adversarial co-evolution," said Bartley Richardson, CrowdStrike's Chief of AI, speaking at the Fully Connected event. "We train and steer the best offensive capabilities to attack, to find ways around defensive operations. But then, we train these defensive models on large-scale infrastructure to learn from those attacks."

The urgency behind the system is clear in CrowdStrike's 2026 Global Threat Report. The fastest recorded eCrime breakout time dropped to 27 seconds. The average fell to 29 minutes, a 65% increase in speed from 2024. In one documented intrusion, data exfiltration began within four minutes of initial access.

AI-enabled adversaries grew their attack volume by 89% year over year. Malware-free attacks accounted for 82% of all detections in 2025. Adversaries also targeted AI systems directly, injecting malicious prompts into generative AI tools at more than 90 organizations and abusing AI development platforms.

CrowdStrike CEO George Kurtz framed the partnership in direct terms. "CoreWeave powers some of the most advanced AI workloads on the planet, and CrowdStrike secures where AI happens," Kurtz said. "Together, we're building a foundation for the agentic era, where security is inherent to AI itself."

On September 30, 2026, CoreWeave launched the CoreWeave Partner Network, a curated group of technology partners whose integrations are validated under real production conditions on the CoreWeave Cloud platform. CrowdStrike is named as one of its anchoring collaborators. CoreWeave also joined CrowdStrike's new AI Partner Specialization program, which spans AI cloud, security, models, data, applications, and services.

CoreWeave co-founder and CEO Michael Intrator pointed to the production environment as the true proving ground. "Few environments put AI to the test more than cybersecurity," Intrator said. "We're proud to power SafeMind across training and inference as CrowdStrike puts specialized AI to work against real-world threats."

CrowdStrike's internal evaluations found SafeMind's defensive model delivered a 29% higher detection rate, six times faster end-to-end remediation, and 99% lower costs for detection and remediation compared with leading frontier models and open-source baselines. Those figures are company evaluations and have not been independently verified.

The zero-day threat environment adds pressure on both sides. CrowdStrike's report recorded a 42% increase in zero-day vulnerabilities exploited before public disclosure. China-nexus threat actors directed 40% of their vulnerability exploitation efforts at edge devices.

NVIDIA CEO Jensen Huang, whose hardware underpins CoreWeave's cloud, described the stakes plainly. "Cyber defense will be among the most compute-intensive applications of AI," Huang said.

Read more: CrowdStrike and CoreWeave bring AI security to machine speed

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.