Submind YouTube summaries
Thumbnail for Justin Boitano, NVIDIA & Daniel Bernard, CrowdStrike | CrowdStrike Fal.Con 2026

Justin Boitano, NVIDIA & Daniel Bernard, CrowdStrike | CrowdStrike Fal.Con 2026

Watch on YouTube

Video summary

At CrowdStrike Falcon.Con 2026, NVIDIA and CrowdStrike unveiled a groundbreaking collaboration designed to revolutionize cybersecurity through artificial intelligence. The core of this partnership is "Safe Mind," a specialized model family developed specifically for defense and offense in the cyber realm, distinct from general-purpose frontier models that adversaries currently exploit. This system integrates two primary components: "Red Tempest," an offensive AI agent capable of simulating sophisticated attacks to find vulnerabilities, and "Blue Solano," a defensive agent that learns from these simulations to create rules and mitigations. These agents operate within a custom harness called Safe Mind, which acts as an exoskeleton, significantly enhancing the capabilities of underlying open-weight models like Neotron by optimizing them for specific security tasks without requiring massive proprietary training data. The operational mechanism relies on a continuous iterative loop facilitated by a "digital twin" of an enterprise environment hosted on CrowdStrike's Falcon platform. In this simulated sandbox, the Red Tempest agent aggressively probes the digital twin to discover attack vectors, while the Blue Solano agent simultaneously develops detection and prevention strategies to neutralize those threats. This process creates an infinite cycle where the system constantly refines its defenses until no exploitable paths remain, effectively hardening the environment before any changes are deployed to production. A key innovation here is the use of open-weight models combined with CrowdStrike's deep domain intelligence from its Falcon sensor; this allows the system to leverage customer attack path data as a threat feed to train better detection models, thereby bending the curve in favor of defenders and providing an asymmetric advantage against nation-state level threats. Beyond the technical architecture, the presentation addressed the broader economic and human implications of AI in security, challenging the fear that automation will replace human professionals. Instead, executives argued that AI acts as a force multiplier, enabling cyber teams to handle exponentially more workloads and solve new problems arising from autonomous agents entering networks. The event introduced "Project Quilt Works," a coalition initiative aimed at unifying the ecosystem to help organizations manage the risks associated with frontier AI models by prioritizing vulnerabilities and communicating complex security issues clearly to non-technical stakeholders. Furthermore, NVIDIA reaffirmed its commitment to open-source foundations like Neotron, ensuring that the digital economy remains accessible and secure through collaborative development rather than walled gardens. The overarching message from both Jensen Huang of NVIDIA and Justin Boitano of CrowdStrike was one of optimism regarding the future of cybersecurity. They posited that while AI introduces new challenges, such as the rise of "agent states" capable of matching nation-state capabilities, it also offers unprecedented tools to stop breaches and close the skills gap in the industry. The ultimate goal is not to remove humans from the loop but to empower them with advanced tooling that makes their roles more effective and efficient. By integrating these cutting-edge AI capabilities directly into the Falcon platform, the partnership aims to raise the bar for preventative detection and response across all industries, ensuring that organizations can operate securely in an increasingly automated threat landscape without succumbing to fear or paralysis.
Read the full video transcript
Here we go. Hi everybody. Welcome back to Falcon 2026. This is day two or day full day with the keynotes of Falcon's conference, the cub's coverage. We did day zero last night, kind of the cube after dark. The big news today, George Kurts gave an awesome keynote and of course the star Jensen came out. George and Jensen, some wonderful banter. DB is here. Daniel Bernard, he's back. Good to see you again. Thanks for coming. Awesome job this morning. >> Thank you. >> Uh you had a great great lineup. And Justin Banano, >> cube alum, good to see you again. >> Good to see you. >> Not much going on, is there? >> It's busy every day. [laughter] >> So you guys kept a good a good secret. Nobody really knew that was coming. >> And if you haven't seen the news, we're going to go through it. I'd like to It was like the chaos monkey. Remember the Netflix chaos monkey? They would release it. But the novel thing is you got red team, you got blue team, you've got a harness. Yep. who you know basically the the setup is the frontier models the general purpose models they weren't built for defenders uh they were really but attackers can use them at will and they're really good at that >> so you guys partnered CrowdStrike and Nvidia to build a purpose-built model for cyber security let's get into it >> sure shall we >> yeah what what blue team red team and a harness >> and harness that's the ingredient >> you had the setup right frontier models have done done a fantastic job bringing AI innovation to the market at large. It's really benefited the adversary. It's time for the defenders to have something and it's time for security to have its own model, its own and it turned into just one model turned into a to a set of models, a model family. And that's where Safe Mind was born. Why? Because we knew we needed a model to do offense and constantly get better and better and better at targeted offensive tactics. And then we needed a model for defense so that the defensive model can learn from all the and all of it learns from all the Falcon platform. We're going to talk about that in a second, but that the defensive model can constantly get better and better and better at being the world's very best defender. Those two things alone don't don't really solve the problem and operationalize a solution. This is where the custom harness comes into play so that you can operationalize the models and and really unleash them in your environment to have the best of offense, the best of defense. And this whole system was trained on Neotron. We're not an accelerated compute company, but we want to accelerate cyber security. And that's where Justin comes into the picture. >> Okay. So, it's a neotron which is an open weights and open- source model customuilt around Neotron. And then the other novel piece is you basically can run this on a digital twin of your enterprise. Is that a cosmos or is that uh th >> this is uh safe mind uh so it's a it's a safe mind platform it is all crowdstrike which is awesome. >> So the digital twin is is is crowd strike. Okay. >> Yeah. >> Which so Okay. So to set it up, so you run the red team, you let it loose, my chaos monkey analogy, >> and it finds all these attack vectors and then the blue team comes in and resolves them and you've got this infinite loop and it just keeps knuckling it down until there are no paths. Right. That's basically how it works. >> That's right. So uh and and we've been a design partner with Crowd Strike. We've been applying it in some of our environments. Uh, and basically what you do is you you uh the the digital twin describes the environment of the of the actual world. Uh, and then to your point, you run the the red agent through the environment and you'll find uh different ways in to uh xfill data, for example, if that's the goal. And then the blue agent will come in and write rules that would have uh detected or prevented the red a the red attack agent from getting through. And that iterative loop basically hardens the environment so that you can be really confident that your cyber teams have all the detections or mitigations in place uh in this digital twin environment that then you move to production. >> And Jensen called the harness an e like an exoskeleton he called it. >> So >> and I was going to say I I feel like that's the part that's always missing in these conversations about AI. People start with the models, right? >> Uh but Frontier is in the harness and people don't realize that enough which is why Jensen's saying it's an exoskeleton. the harness uh you can lift any model you know uh much much higher. I think you guys in some of your uh agentic systems will see uh just the harness lifting the model by you know 20 30 points in accuracy in these domain specific goals and then in addition to that then you can post-rain an open model and get super lowcost beyond frontier capabilities through this harness optimization and then model post training. So, how do you think this will change the tokconomic conversation? I mean, to me, this is high value. >> Yeah. Cyber has really been kind of like living in a parallel universe to tokconomics and I think we're we're we're starting the great convergence of it and we're starting it here at CrowdStrike where the SISO and the CIO now have a security token line item that they didn't necessarily have before and um you know it's more of an outcome based model but I think that that's where the market's gone in AI and it's where we need to take cyber security. >> Does that change the way you price this stuff? Um, >> we're still using like Falcon Flex ends up being, no pun intended, the perfect harness. >> Yeah. Right. >> For there you go. For uh for how we can price this and package it. Um, ultimately the models are going to also live natively in the in the platform. Sort of like fluoride and water. We want to make raise the bar for everybody in terms of the preventative detection and response capabilities of of the Falcon platform. But then specifically the harness and and and using it as a standalone for organizations that really want to identify their their security operations or identify their security operations teams. Um that's that's where it'll be an additional cost. So Neotron is a leading one of the leading open-source openweight models. And so what was the process like to sort of customize that? I mean for us >> yeah you you want you you wanted to do it with openw weight models. you had to have open weight models. So that's why you couldn't really do it with an entropic or an open AI although you had of course you had open AI on the stage which is interesting but what's the process like because it because enterprises want to do this as well what can they learn from this? Yeah. So, uh maybe stepping back for a second. So, our commitment to Neotron is to provide uh open intelligence and you said this is truly open. So, open data sets, open techniques and the techniques are like where we're teaching how to post train and then open model weights. Um and we we do that all as open source. Now, what CrowdStrike have is the domain intelligence. I'll say the ultimate sensor, the Falcon sensor, and it's the the perception system that really understands enterprise environments. What are they running? uh you know both the endpoints, identity, uh networking uh and and all of that perception of what's going on in enterprise infrastructures. You kind of know the attack paths that people might be trying to exploit. Um and so combining that domain knowledge, that domain uh specific data about cyber security with an open model, you then can post- train a model to be, you know, super good at uh either attack or defense. Um and and I'd say the nice thing is um I'll say uh what's interesting is uh is these agent traces like agents are uh a new threat actor right uh and if traces were shared openly that data would be a new threat feed that everybody would train into their detection systems. Now uh for a lot of companies uh you know because of terms of use they won't allow you to share those those uh those traces but what's nice is um because it's all they've built from open um basically crowdstrike can use their attack paths in customer environments as a threat feed to then train better detection models as well. So ultimately the goal is uh bend the curve and give the defenders this asymmetric advantage >> and we should talk about that a little bit because George again his keynote was awesome. He had the pyramid and at the top of the pyramid, the old pyramid was nation states. You remember, right? Nation states. Oh, wow. They've got incredible capabilities. But, you know, down the bottom of the pyramid, they don't have as many capabilities. Well, now the pyramid's flattened. Well, he actually put agents at the top. >> Agent state at the top. >> Agent agent state he called it. And then he then he said, I got a new graphic. He collapsed the pyramid. It's just a flat line so that anybody can prompt. >> Yeah. you know, with with nation state capabilities and that's that's new. That's kind of scary. Now, at the same time, Jensen said we, you know, we don't have to be dumerous. Um, >> yeah. >> So, why are you an optimist? >> I'm an optimist because every single person on planet Earth has gotten a ton more capabilities than they had before. Like, life's better now than it was 10, 15, 20 years ago. And we're going to live longer, too. And we're also going to live lives with fewer breaches because cyber security just got a lot better. You know, this is the power and the magic of accelerated computing. Um, the same way that every industry is being revolutionized by AI, I think we're entering this new chapter where cyber security is being revolutionized by AI, by our frontier system and that it's specialized for our market. You know, I think that's a big part of this next chapter of broader AI adoption. I'm an optimist. Jensen told us our job in the market is calm everybody down. And the way we're going to calm everybody down is we're going to stop more breaches than we've ever stopped them before. There's no reason to fear the adversary. There's no reason to fear AI. You got to make sure you have the right protection, the right systems, the right people, the right processes, and you're going to be just fine running a great cyber security program with the most cutting edge technology on the market. >> You an optimist? I'm sure you are. You better be in this business. >> Well, I think anything you'd add to that? One of one of the things that's always been the case in cyber security is you've always had this uh I'll call it shortage of cyber professionals. So I think the technology is going to help you know 10x 100x the cyber defenders and ultimately I think uh if we can you know put the tools in the hands of the defenders and give them this differential advantage. It's a it's a good thing for every critical industry. >> And this came out of a stealth lab. >> It did. >> You guys really don't talk about >> secret project super intelligence lab. >> George said yeah super intelligence lab and he said that's not the that's not the announcement. The announcement is Blue Salano, well, Red Tempest is the is the the red team, offensive, Blue Solano is the the defensive and then and the safe mind is the harness. And I described this sort of infinite loop where you just keep getting better and better and better in the digital twin. Okay, now I deploy that into my environment. Then what happens? My environment changes. I then create an update of the digital twin. I run it again and I deploy it. What if something goes wrong? What should how should customers think about that? I mean, it's like the new concept of a of a window. It's not a patch window anymore. It's like a window. If something goes wrong, I got to fall back. How should they think about that? >> Well, having an off switch is really important. Also, having humans in the loop and in control was another big part of his keynote. Like, this isn't made to get the humans out of the way or to minimize the role of humans in security at all. It's made to make the human 10, 20, 30x what they could do before. A lot of people think AI is going to create a lot less work and make life easier. I don't think that's the right narrative. I think workloads only gone up one direction cuz productivity levels have gone up to a whole new level. So like we're going to need more people tomorrow than we needed yesterday. You know, when autopilot came out on the plane, you know, it's not like you didn't need pilots. We need more pilots than we need because people want to go to more places >> because it's faster, easier, and safer to fly. The same thing is happening in security. You're going to need more people. Agents are going to help us with the skills gap shortage, but there's going to be new problems to solve, new opportunities, new defense, and this is how the whole industry moves. And it's going to be everybody that's here on the floor you got look that you look out to. It's not just CrowdStrike. Uh the vision is that this kind of technology and what we did today with Nvidia, we can bring to the entire market. >> I mean, that's an interesting observation. I'm sure you guys like I am, I mean, never been busier. I got all these projects now that I'm managing these agents running around reporting back to me and I and I have to prioritize. Right. It's like I'm sure you're seeing the same thing. Yes. You your Nemo claws, right? >> Claws running around everywhere in that place, you know? >> Right. So, what you know, at GTC this year, I mean, Nemo Claw was like the timing of that was was was pretty interesting. Um, and of course, we saw the acquisition. What's the state of Nemo Claw these days? It's still uh you know I think a an important building block for teaching developers uh how to take open models, open harnesses and open runtimes and then put them together in their environments. Um you know we're we're most pleased when there's a partner like CrowdStrike that has the scale and the domain expertise to take that you know embedded into their platform and then really scale it to the broader cyber security market. We we love that across every vertical industry you could imagine. Um but uh but Nemo claw is really a reference for developers and I I think within enterprises there's still the need to be able to you know sometimes build a uh you know use case specific AI agent to drive a very you know domain specific use case >> and I want you I want you Justin to address Neotron because a lot of people say oh well Neotron of course Nvidia is doing that because you know all their customers are now building chips so they're going to build openweight models. I I to me it's all about the developer community but but what was the genesis of Neotron? Why did you guys start that? Obviously there's a US China thing as well that is advantageous but >> yeah I think what was the genesis? >> I think from from a macro standpoint if you step back and you look at even uh the digital economy uh in the world right now 80% of the digital economy runs open source. So just on first principles uh open source models if the intelligence is within you know uh a distance of frontier people will run on open source. Uh so I think just on first principles Jensen said makes sense we need to be providing um I'll say US-based you know near frontier open models is this foundational digital intelligence that people can post train and customize into all their different applications and use cases. So as a compute builder uh obviously we have compute to continue to invest uh in building this open foundation and as Jensen said we're on Nemoron 3 uh you know we're talking about Nemoron 4 we're talking about Nemoron 5 it is a commitment that we are going to continue to do into the future and I think that gives partners confidence to then build on the platform customize it and then go build this digital intelligence into uh new domain use cases. >> It's probably a good bet you guys have a decent dos say ratio. Yeah, >> by my track record, >> it's a good bet for us. Like, if we're going to build something that's going to last, we need to build it on somebody that we know is going to last, what better partner to do it where one, they want us to be successful in solving this problem in cyber, and they want to support us on that journey, and two, it's also good to partner with the largest company on planet Earth. Not a bad idea. >> What's the go to market on Safe Mind and Red Tempest and Blue Salano? Are they kind of additions to Falcon Flex? When can I get it? So, it's all starting uh with our Quilt Works partners because they're trusted and we want them to be the first uh the first users, the the the beta launches of the of this. Um the models are coming into the platform and eventually we'll be able to also bring this to market to customers that are not even Falcon Platform customers today. So, and of course we want to get them on the platform so they can start to see the benefits of everything in production. Um, but this will all roll out over the upcoming couple months and it's a really innovative piece of technology that came out today. We're super excited and very very uh privileged to work so closely with NVIDIA. You heard Jensen himself talking about the the capabilities, the testing, the benchmarking, the outcomes, and I think it's a really exciting new chapter for CrowdStrike. >> Project Quilt Works. I I can't remember what I can and can't say. Um, so explain Project Quilt Works and tell us what you can tell us. >> Yeah, sure. So we saw some Frontier Labs publish some new models projects project project Glass Wing for example and it kicked off a bunch of questions engagement sometimes hysteria in the the market and what we realized is we need to unify our ecosystem which is sort of on display here today uh unify the the thousands of partners we work with and unify them in the pursuit of understanding frontier AI risk understanding what Quiltworks is a coalition of partners that help customers understand what do I do with these vulnerabilities. Then I need to prioritize them. Then I need to understand which ones I can patch and which ones I can't patch and then ultimately communicate this in a in an intelligible way for a non-security audience that now all of a sudden is thrust into the world of cyber security. It's hard to do cyber security on chat GBT, which is what a lot of SISOs have to respond to from their boards and and executive teams that now proclaim to be cyber security experts. So >> with confidence >> with confidence. Yeah. Copy paste. They're copy paste experts. You know what I mean? >> So with Quilt Works, we we announced some of the stats on our on our last earnings call. Hundreds of millions in pipeline, etc. And then closed closed business. some really interesting use cases of helping very large organizations uncover their vulnerabilities and work them through the the system so that they're so that they're safer. We just productized Quilt Works by the way yesterday. We announced that and we did it using Neimotron also in a technology we published called Falcon IQ. It layers on top of the Falcon platform and it runs the Quilt Works playbook for you. So that if you're a partner, if you're one of our Quilt Works partners, and we just got a ton more applications for more companies to become Quilt Works partners on the back of today's announcement and yesterday's, it does the Quilt Works assessment for you. It does the paperwork and the process for you so you can turn over the nice reports. It really ends up for us becoming an upselling platform adoption machine. And that's what's so exciting about Quote Works. Rather than let everybody sit in their own silo and be worried about the the the existence of AI and cyber, it's the crowd and crowd strike. Bring everybody together, get them marching in the same direction, let everybody do their own thing, but set up a set up a framework and a strategy and go execute really really well. >> Excellent initiative, great great value for the industry. All right, last question. Um, what are you guys working on that uh you can give us a little glimpse of in the future? Where do you where do you want to take this? I'll say I think Jensen even sort of talked about this a bit is uh within every company uh you know not only for Nvidia do we have 40,000 plus employees but we're going to have hundreds of thousands of agents. So really the question is how do you start to observe uh you know find new agents that are entering your environment uh and then be able to secure that uh in in your running environment all the time and I think that's the ongoing pursuit make that fully autonomous you know continue to invest in you know frontier models and these capabilities to give cyber defenders the better uh tooling to see and observe what's going on in their environment. >> Guys really exciting news today and great presentation. Congratulations on all the effort and you you're communicating something that I think is really important for the industry to understand and you're not just scaring them. You're delivering a solution. So we appreciate that. >> Thank you. Thanks for coming back. >> Thank you. Thanks for having us. >> Justin, good to see you. >> Thank you. >> All right. Thank you for watching. This is Dave Volante for Rebecca Knight. We'll be right back from Falcon 2026. You're watching the Cube.