Cybersecurity & Privacy — 2026-03-19

CISA Urges Hardening of Endpoint Management Systems After Iranian Hackers Wipe 200K Stryker Devices

CISA issued a fresh advisory urging organizations to harden Microsoft Intune environments after Iranian hacktivist group Handala compromised Stryker's Intune admin account and pushed a coordinated wipe across 200,000+ devices in 79 countries. The attack vector, endpoint management platform abuse, represents a novel threat class. CISA and FBI are jointly investigating with Stryker executives.

Analysis
Both the 0400 INTSUM and IC Brief tracked the Stryker/Handala attack. Today's CISA Intune advisory represents the government's formal response, elevating endpoint management platform abuse as a systemic threat class beyond the single-incident Stryker response.

View in full brief →

UNCLASSIFIED // OPEN SOURCE