logo

Lock down Microsoft Intune, feds warn after Stryker attack

ID: b574fc53-aaff-5eee-8e08-82b978d280d6

STIX ID: report--b574fc53-aaff-5eee-8e08-82b978d280d6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive summary:** The report describes a targeted intrusion attributed to Handala (linked to Iran) that abused Microsoft Intune to wipe employee devices and knock parts of Stryker's networks offline, disrupting shipping and ordering systems; CISA has issued an alert advising organizations to harden Intune, follow Microsoft's guidance, and apply least-privilege role-based controls to prevent similar account creation and wipe actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.