Two Models Fighting Inside a Digital Twin of Your Environment Until No Path Remains: CrowdStrike and Nvidia Launch SafeMind

CrowdStrike unveiled SafeMind with Nvidia at Fal.Con 2026, built from two models: Red Tempest, an offensive model emulating adversaries to find attack paths, and Blue Solano, a defensive model fine-tuned from Nvidia Nemotron 3 Super that deploys remediations, with a Nemotron 3 Ultra instance orchestrating the defensive agent harness. It runs as a closed loop: Falcon sensors build a digital twin of the enterprise environment — asset inventories, identity stores, threat graphs, adversary intelligence — Red Tempest attacks it repeatedly, and Blue Solano learns from each attempt and deploys new detections until no viable attack paths remain. Training data includes Falcon sensor telemetry, CrowdStrike threat intelligence, Falcon Complete MDR annotations and 15 years of incident-response knowledge. CrowdStrike says internal evaluations found Blue Solano more accurate than the frontier models tested, at 99% lower cost.

The Novelty Is What It Attacks

Automated red teaming is not a new concept. What differs here is the target: it does not run against production. Falcon sensors first replicate the enterprise environment into a digital twin — asset inventories, identity stores, threat graphs and adversary intelligence all included — and Red Tempest attacks that copy repeatedly. Blue Solano learns from each attempt, identifies the weaknesses, deploys new detections, and the loop continues until no viable attack path can be found. The two models come from different places. Red Tempest is an offensive model built for advanced attack scenarios. Blue Solano is fine-tuned from Nvidia Nemotron 3 Super and works from battle-tested remediation measures, with a Nemotron 3 Ultra instance orchestrating the defensive agent harness. The training material is CrowdStrike's existing inventory: Falcon sensor telemetry, its own threat intelligence, Falcon Complete MDR annotations and 15 years of incident-response knowledge, post-trained onto Nvidia's open Nemotron models. Nvidia ran it against itself too, in a high-fidelity cyber agent environment that is a digital twin of its own internal accelerated computing infrastructure. Per Nvidia VP of enterprise AI Justin Boitano, the red team agent combed the environment and identified exploitable attack paths, the blue team agent applied safeguards, and the cycle repeated until all paths were blocked.

Read the "99% Lower Cost" Carefully

CrowdStrike's internal evaluations claim Blue Solano is more accurate than the frontier models tested while costing 99% less. That is vendor self-assessment, and commentary has noted the caveat: the disclosed controlled test shows a validation-heavy open pipeline outperforming a frontier system on selected measures, leaving broader generalization an open question. Translated into selection terms, the figure says that on tasks and metrics CrowdStrike defined itself, a purpose-trained mid-size model is more economical than a general frontier model — not counterintuitive in a vertical domain. It does not generalize to "specialized models beat frontier models." If you are evaluating it, the questions worth asking are how the evaluation set was constructed, which attack classes it covers, and what the false positive rate looks like when detections that worked in the twin are moved to the real environment.

The Context Numbers and How It Ships

CrowdStrike's framing figures: AI-enabled attacks rose 89% over the past year, and the fastest eCrime breakout time has compressed to 27 seconds — which the company summarizes as breakout time effectively becoming runtime. That framing serves its product narrative, but the 27-second magnitude is worth recording on its own: the window for human response is essentially gone, which is the direct reason automated defense is being pushed forward. On availability, SafeMind will be native in CrowdStrike Falcon, with direct model access through the Project QuiltWorks trusted access program, and CoreWeave providing cloud infrastructure for training and inference. CEO George Kurtz called it the first complete agentic system for cybersecurity, and the models came out of a newly formed Cyber Superintelligence Lab. The practical implication for readers: in the near term this matters directly only to enterprises already on Falcon. The more general point is the trend — shipping an offensive model as part of a product is something most vendors had avoided. This site recently covered OpenAI confirming Astra crossed its Critical cybersecurity threshold and releasing it in tiers. Both point the same way: offensive capability is moving from "should not be built" to "built, with access controlled."

via: SiliconANGLE, CSO Online, eSecurity Planet, Quartz