Cybersecurity & Privacy — 2026-03-20

Stryker Cyberattack Post-Mortem Raises Questions About Device Management Tool Exposure

Post-incident analysis of the Iran-linked Handala group's Stryker attack reveals the initial compromise vector was an exposed device management platform that provided access to 80,000+ endpoints. The attack impacted Stryker's Microsoft environment and wiped thousands of mobile devices. The incident exposes systemic risk in medical device manufacturers' IT infrastructure as Iranian cyber operations increasingly target US commercial entities during the conflict.

View in full brief →

UNCLASSIFIED // OPEN SOURCE