Technology & OSINT — 2026-03-20
CISA Issues Intune Security Advisory After Iran-Linked Wiper Attack Exploits Device Management
CISA and FBI jointly warned organizations about vulnerabilities in Microsoft Intune device management after the Handala group weaponized compromised Intune credentials to execute a mass wiper attack on Stryker's global network. The advisory details how infostealer malware harvested Intune admin credentials, enabling remote factory resets across the company's device fleet. The attack model -- targeting centralized device management rather than individual endpoints -- is novel for Iranian threat actors.
View in full brief →