Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA urges Intune hardening for U.S. organizations

Public Sector Action
First reported
Last updated
Happening score
H score 80
1 unique sources, 2 articles

Summary

Hide ▲

CISA urged U.S. organizations to harden Microsoft Intune and related endpoint management controls after the Stryker attack showed how those systems could be abused to wipe devices and expand damage. The alert matters because it aims to reduce the risk of similar malicious activity targeting other networks and administration consoles. CISA tied the warning to March 19, 2026 guidance that pushes stronger controls for privileged access and sensitive actions.

Related Happenings

CISA recommends continuous secrets scanning and stronger key management after GitHub leak

Defensive Guidance
H score26 First: 13.07.2026 18:03 Last: 13.07.2026 18:03 Sources 1

About this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...

NHS awareness campaign and guidance on unauthorized patient-data access

Public Sector Action
H score8 First: 10.07.2026 12:00 Last: 10.07.2026 12:00 Sources 1

About this happening: The NHS launched a new awareness-raising campaign and guidance to curb unauthorized access to patient data across staff and healthcare organizations. The initi...

NHS patient-data unauthorized-access guidance

Advisory/Mitigation
H score7 First: 10.07.2026 12:00 Last: 10.07.2026 12:00 Sources 1

About this happening: The NHS issued patient-data unauthorized-access guidance that tells healthcare organizations to tighten monitoring, reporting, and access controls across staff systems. The ro...

BEC defensive guidance for exposed-credential and account-misuse risk

Defensive Guidance
H score14 First: 30.06.2026 17:00 Last: 30.06.2026 17:00 Sources 1

About this happening: BEC defenders are being pushed toward tighter training and account-response controls as operators combine AI-generated business correspondence, call-center press...

Microsoft Teams admin policy adds approval-based control for third-party bots

Security Tool/Service
H score11 First: 30.06.2026 13:52 Last: 30.06.2026 13:52 Sources 1

About this happening: Microsoft Teams introduced an admin policy that lets organizers prevent third-party bots from joining meetings without approval. The control improves visibility over e...

Timeline

  1. 19.03.2026 13:02 1 articles · 3mo ago

    Handala compromises Stryker Microsoft environment and wipes Intune-managed devices

    Exploitation Observed

    Handala claimed a March 11, 2026 compromise of Stryker Corporation's Microsoft environment, saying it stole 50 terabytes of data and used Microsoft Intune's built-in wipe command after creating a new Global Administrator account from a compromised administrator account, which erased nearly 80,000 devices.

    Show sources
  2. 19.03.2026 13:02 3 articles · 3mo ago

    CISA urges Microsoft Intune hardening for U.S. organizations

    Mitigation Patch Update

    On March 19, 2026, CISA urged U.S. organizations using Microsoft Intune and other endpoint management software to harden administrative controls after the Stryker Corporation compromise, recommending least-privilege RBAC, MFA, Microsoft Entra ID protections such as Conditional Access and risk signals, and multi-admin approval for sensitive actions like device wipes, application updates, and RBAC changes.

    Show sources