CrowdStrike debuts SafeMind, pairing Red Tempest with Blue Solano
TL;DR
- Red Tempest finds the exploit path and Blue Solano closes it in the same adversarial loop; cycle output feeds directly into Falcon detections, creating a self-tightening defense.
- CrowdStrike claims 29% higher detection rate, 6x faster remediation, and 99% lower cost versus leading commercial models run through standard enterprise security stacks.
- Jensen Huang appeared at Fal.Con as both Nvidia CEO and a confirmed paying CrowdStrike customer; SafeMind has already replicated Nvidia's own internal IT environment using Falcon sensors.
CrowdStrike Chief Executive George Kurtz used his Fal.Con 2026 keynote in Las Vegas to argue that attacker breakout time has effectively hit zero. His answer, unveiled the same morning and covered by SiliconANGLE, is SafeMind: two agentic models that run against each other continuously inside a digital twin of the customer's environment.
The offensive model is called Red Tempest and was trained partly on 15 years of CrowdStrike incident-response data. Its counterpart, Blue Solano, remediates whatever Red Tempest finds. The loop keeps cycling until no viable attack paths remain.
Both models were built on Nvidia's Nemotron open models by a new CrowdStrike research group called the Cyber Superintelligence Lab, with CoreWeave supplying AI Cloud for training and inference. SafeMind runs natively inside Falcon; standalone model access is being offered through a program CrowdStrike calls Project QuiltWorks.
"The future of cybersecurity won't be defined by AI that simply identifies threats, it will be defined by AI that defeats them," Kurtz said in the company's release. Nvidia founder and CEO Jensen Huang framed the collaboration as "NVIDIA Nemotron open models with CrowdStrike's deep cybersecurity expertise, trusted security data, purpose-built agent harnesses, rigorous evaluations, and safeguards."
Dave Vellante, theCUBE Research co-founder and chief analyst, called it the strongest Fal.Con keynote he had seen in five years. His paraphrase of Kurtz's argument: "Every year at this conference, George steps up and says breakout time has gone from two minutes to 72 seconds, down to 30 seconds. And now he's like, it's done. It's just runtime. There is no breakout time." Vellante also relayed Kurtz's line that in the new hierarchy, "the nation state, the agent state he called it, is a prompt."
The performance claims, a 29% higher detection rate, 6x faster remediation and 99% cost savings against frontier and open-source baselines, come from CrowdStrike's own evaluations in the release. Krista Case, another theCUBE analyst, described the framing as "a wake-up call for the industry, even though attacks like it aren't yet happening at scale."
This is our third cybersecurity alert of the day, arriving alongside coverage of Aurora ransomware pairing Cursor with Claude Sonnet and cryptographer Matthew Green's warning that AI may make lawful hacking impossible.
What others are reporting
-
CrowdStrike Read →
First-party source with the headline performance claims: 29% higher detection, 6x faster remediation, 99% cost reduction vs leading commercial models; formal Falcon availability confirmed.
SafeMind brings offensive and defensive models together in a system trained on CrowdStrike's unique cyber data.
-
NVIDIA Blog Read →
Nvidia frames SafeMind's harness as a reusable architectural pattern for robotics and edge compute, not just security; stresses open Nemotron enables post-training on proprietary data without external providers.
Attacks are now automated. Defense has to be, too.
-
CSO Online Read →
Original reporting: Huang confirmed as paying CrowdStrike customer with Nvidia's own internal IT running on Falcon; frames SafeMind as CrowdStrike's answer to commercial AI guardrails blocking defenders.
The real gap that I saw was that the attackers had frontier AI and the defenders didn't. That changes now.
-
Cyber Daily Read →
Security trade press angle: training on 15 years of CrowdStrike IR fieldwork and Falcon telemetry is the distinguishing factor over general-purpose AI competitors.
The future of cyber security won't be defined by AI that simply identifies threats; it will be defined by AI that defeats them.
Originally reported by siliconangle.com
Read the original article →Original headline: CrowdStrike Unveils SafeMind With Red Tempest and Blue Solano, Twin Agentic Models Built on Nvidia Nemotron