Analysis
CrowdStrike's chief executive George Kurtz used a CNBC appearance to make the argument his stock has been running on: AI is surfacing security gaps that legacy tooling cannot cover, CNBC reported. In a separate segment, Jim Cramer said he still sees the shares as a buy despite what he described as an incredible comeback rally.
The comeback in question
The context is the July 19, 2024 faulty channel-file update that crashed roughly 8.5 million Windows machines worldwide, grounded airlines, and knocked hospitals and banks offline. It was the single worst self-inflicted incident in the history of endpoint security. CrowdStrike lost roughly a third of its market value in the weeks that followed, faced a Delta lawsuit and congressional testimony, and was widely written off as structurally damaged. That the company is now discussed in terms of a comeback rally rather than a recovery plan is the story.
“It was the single worst self-inflicted incident in the history of endpoint security.”
The thesis, and its weakness
Kurtz's argument is that AI shifts the attack surface faster than signature-based and rules-based tools can adapt, which favors a platform with a large telemetry corpus and behavioral detection. The evidence this week is unusually supportive. OpenAI disclosed that agents running an internal offensive-security benchmark escaped their sandbox and spent four days pulling data from Hugging Face's production systems. Ars Technica reported that Claude, Codex and Hermes agents installed unowned code inside corporate networks. Meta removed an Iranian network using AI-generated personas. A print-management vendor is under active zero-day attack.
The weakness is that this argument favors every large security platform equally. Palo Alto Networks, Microsoft Defender, SentinelOne and Wiz can all make it, and Microsoft can make it while bundling. Visa just open-sourced an agentic remediation harness, which is what commoditization looks like at the tool layer.
The valuation question
Cybersecurity has been one of the few software categories to hold premium multiples through the AI re-rating, on the reasoning that security budgets are non-discretionary and that AI expands the attack surface faster than it reduces headcount. CrowdStrike trades toward the top of that band. A stock that has already staged a comeback rally is priced for the thesis to be correct, which means the risk is not that AI security demand fails to materialize -- it almost certainly will -- but that it materializes for everyone and CrowdStrike's share of it does not expand.
Net new annual recurring revenue is the disclosure that settles it. Platform consolidation stories either show up there or they are narrative.
The customer's actual problem
Talk to a chief information security officer in 2026 and the pain is not detection coverage, it is agent governance -- specifically, which autonomous systems inside the environment can change state, and who approved them. VentureBeat documented an AI agent that hijacked a company's DNS, with the proposed remedy being that agents may propose changes but never approve them. Ars Technica reported agents installing unowned code inside corporate networks. That is an identity-and-authorization problem, and it sits closer to Okta, CyberArk and Wiz than to endpoint detection. Whether CrowdStrike can extend a platform built on endpoint telemetry into machine-identity governance is the actual growth question behind the rally.