متتبع أزمة إيران-الخليج 2026
CC
Events Archive
strikeMar 19, 2026

Microsoft Intune: Lock it down, warn feds after Stryker

Summary

Lock down Microsoft Intune, feds warn after Stryker attack Iran-linked attackers wiped employees' devices using Intune The US government has urged companies to better secure Microsoft Intune, an endpoint management tool that was abused in last week's cyberattack against med-tech firm Stryker. Handala, a group linked to Iran's intelligence agency, claimed responsibility for the attack, which knocked some of the surgical equipment maker's networks offline and continues to affect shipping and ordering systems. Stryker has publicly said the attack affected its Microsoft environment, and a source familiar with the investigation confirmed to The Register that the attackers wiped employees' devices using Intune. Microsoft to date has declined to comment. In a Wednesday security alert, the US Cybersecurity and Infrastructure Security Agency (CISA) said it is "aware of malicious cyber activity targeting endpoint management systems of US organizations" following the Stryker intrusion, and urged companies to follow Microsoft's best practices for securing Intune. Redmond published this guidance three days after the cyberattack. - Iran's cyberattack against med tech firm is 'just the beginning' - Iran-linked cyber crew says they hit US med-tech firm - Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations - Another massive security snafu hits Microsoft, but don't expect it to stick Among the recommendations: Use principles of least privilege when designing administrative roles. This can prevent someone who has breached Intune – as appears to be the case in the Stryker intrusion – from creating new admin accounts and using these to control employees' access to internal systems and perform wipe commands. Companies should use Intune's role-based access controls to assign only the minimum permissions necessary to each role for complete day-to-day operations. ®

Actors involved

USIran

Sources

  • Jessica LyonsBy Jessica Lyons

    Lock down Microsoft Intune, feds warn after Stryker attack Iran-linked attackers wiped employees' devices using Intune The US government has urged companies to better secure Microsoft Intune, an endpoint management tool that was abused in last week's cyberattack against med-tech

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIranUN
1 source

US forces struck the tanker Settebello in the Gulf of Oman on June 10, killing three Indian crew members when munitions hit the engine room and adjacent areas. Maritime tracking data indicate the vessel had transported Iranian oil under US sanctions for several years and conducted offshore transfers prior to the strike.

The US military described the action as a precision operation, while reports note the ship was stationary at the time.

Location: Strait of Hormuz
strikeUnverifiedUSIranChina
1 source

The Andaman and Nicobar Islands are the site of Indian infrastructure projects, including the Great Nicobar Project and a proposed greenfield airport intended for civilian and naval use. An analysis published by the Indian defence portal IDRW states that U.

S. officials regard the developments as strengthening maritime security, surveillance and logistics in the Indo-Pacific. The islands’ location has long been cited in Indian statements as relevant to New Delhi’s maritime responsibilities in the Indian Ocean region.

Location: Strait of Hormuz
strikeUnverifiedUSIranProxyRussia
1 source

According to Kpler data, four commodity vessels crossed the Strait of Hormuz on Monday—two exiting (one carrying petrochemicals and one empty) and two entering (a bitumen tanker and an oil tanker)—down from seven the prior day, with no very large crude carriers or liquefied natural gas tankers observed.

Yemen's Houthis stated they were imposing a naval blockade on Saudi Arabia. The UK Maritime Trade Operations agency reported receiving multiple accounts of a tanker struck by an unknown projectile in the strait, while Greek shipping company Dynacom Tankers stated that two of its vessels were hit by projectiles off Oman and a third by a drone at Russia's Novorossiysk terminal.

Location: Strait of Hormuz
strikeUnverifiedUSIsraelIranProxy
1 source

U.S. and Iranian forces have conducted daily strikes in the Strait of Hormuz region following the collapse of an interim ceasefire, according to reports. The Trump administration has stated openness to diplomacy while announcing further retaliation for attacks on U.

S. personnel, and gasoline prices have risen amid the renewed exchanges. An analyst at the Center for Strategic and International Studies described the escalations as reflecting possible miscalculations by both sides, without confirmed evidence of their long-term effects.

Location: Strait of Hormuz