CrowdStrike debuts SafeMind, pairing Red Tempest with Blue Solano
TL;DR
- SafeMind runs Red Tempest, an offensive model trained on 15 years of CrowdStrike incident-response data, against a defensive counterpart called Blue Solano in a closed loop.
- Both models were built on Nvidia Nemotron open models by a new CrowdStrike research group called the Cyber Superintelligence Lab, with CoreWeave providing AI Cloud for training and inference.
- SafeMind ships natively inside Falcon, with standalone model access offered through a program CrowdStrike calls Project QuiltWorks.
CrowdStrike Chief Executive George Kurtz used his Fal.Con 2026 keynote in Las Vegas to argue that attacker breakout time has effectively hit zero. His answer, unveiled the same morning and covered by SiliconANGLE, is SafeMind: two agentic models that run against each other continuously inside a digital twin of the customer's environment.
The offensive model is called Red Tempest and was trained partly on 15 years of CrowdStrike incident-response data. Its counterpart, Blue Solano, remediates whatever Red Tempest finds. The loop keeps cycling until no viable attack paths remain.
Both models were built on Nvidia's Nemotron open models by a new CrowdStrike research group called the Cyber Superintelligence Lab, with CoreWeave supplying AI Cloud for training and inference. SafeMind runs natively inside Falcon; standalone model access is being offered through a program CrowdStrike calls Project QuiltWorks.
"The future of cybersecurity won't be defined by AI that simply identifies threats, it will be defined by AI that defeats them," Kurtz said in the company's release. Nvidia founder and CEO Jensen Huang framed the collaboration as "NVIDIA Nemotron open models with CrowdStrike's deep cybersecurity expertise, trusted security data, purpose-built agent harnesses, rigorous evaluations, and safeguards."
Dave Vellante, theCUBE Research co-founder and chief analyst, called it the strongest Fal.Con keynote he had seen in five years. His paraphrase of Kurtz's argument: "Every year at this conference, George steps up and says breakout time has gone from two minutes to 72 seconds, down to 30 seconds. And now he's like, it's done. It's just runtime. There is no breakout time." Vellante also relayed Kurtz's line that in the new hierarchy, "the nation state, the agent state he called it, is a prompt."
The performance claims, a 29% higher detection rate, 6x faster remediation and 99% cost savings against frontier and open-source baselines, come from CrowdStrike's own evaluations in the release. Krista Case, another theCUBE analyst, described the framing as "a wake-up call for the industry, even though attacks like it aren't yet happening at scale."
This is our third cybersecurity alert of the day, arriving alongside coverage of Aurora ransomware pairing Cursor with Claude Sonnet and cryptographer Matthew Green's warning that AI may make lawful hacking impossible.
Originally reported by siliconangle.com
Read the original article →Original headline: CrowdStrike Unveils SafeMind With Red Tempest and Blue Solano, Twin Agentic Models Built on Nvidia Nemotron