
Following a cyberattack where medical device company Stryker’s systems were wiped using a vulnerability in Microsoft Intune, CISA advised U.S. businesses to follow Microsoft’s guidelines to enhance the security of their Intune endpoint management.
Microsoft released advice on strengthening Intune security controls shortly after Stryker suffered a breach. The breach was claimed by Handala, a hacktivist group with ties to Iran that is pro-Palestinian.
The attackers said they exfiltrated 50 TB of data before using the integrated wipe function in Microsoft’s cloud-based Intune tool to wipe almost 80,000 devices on March 11.
As a source aware of the incident told BleepingComputer, the attackers gained access by creating a new global administrator account after compromising an existing administrator account.
Now, CISA has urged all U.S. organizations to improve the security of their Intune setups to prevent similar attacks on their networks.
The U.S. cybersecurity agency stated on Wednesday, “CISA is tracking malicious cyber activity targeting U.S. organizations’ endpoint management systems, stemming from the March 11, 2026, attack on Stryker Corporation, a medical technology firm based in the U.S., that impacted their Microsoft environment.”
“To protect against similar malicious cyber activities, CISA is encouraging organizations to enhance security configurations for endpoint management systems using the provided recommendations and resources.”
CISA’s recommendations, which apply to Microsoft Intune and other endpoint management solutions, require IT administrators to restrict admin privileges giving only necessary permissions using Microsoft Intune’s role-based access control (RBAC).
Admins should also use MFA and good privileged access practices to prevent unauthorized access to privileged functions in Intune (using Microsoft Entra ID features like Conditional Access, risk signals, and MFA) and require multi-admin approval for actions that are especially sensitive, such as device wipes, application upgrades, and RBAC changes.
Microsoft says, “These practices, when combined, allow you to move away from relying solely on ‘trusted administrators’ and towards a more secure administration that is more secure by design: least privilege to limit the damage, Microsoft Entra-based controls to verify users and ensure they are who they claim to be, and multi-admin approval to control the changes that are most critical.”
Handala (also known as Handala Hack Team, Hatef, Hamsa), the group that claimed the Stryker cyberattack, emerged in December 2023 and is a hacktivist group that attacks Israeli organizations using data-wiping malware for Windows and Linux.
They have been associated with Iran’s Ministry of Intelligence and Security (MOIS) and are known for stealing and sharing confidential information from hacked systems.
#cisa #highlights #incident #intune! #microsoft #news #organizations #secure #stryker #vulnerability — News
© Bulletproof Servers. All rights reserved.