FBI, CISA warn on Microsoft Intune risks after Iran-linked cyberattack on Stryker
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是美国联邦网络安全机构建议组织加强微软Intune的保护,因为伊朗相关的网络攻击影响了斯特瑞克公司。攻击者入侵了Intune系统,清除了大量设备的数据。CISA和FBI发布了安全建议,包括多因素认证、最小权限访问和双重审批机制。此外,他们还采取行动关闭了黑客的网站,并提到伊朗领导人的死亡。 接下来,我需要把这些要点浓缩到100字以内。重点包括:联邦机构的建议、攻击手段、安全措施和后续行动。确保语言简洁明了,不使用复杂的术语。 最后,检查字数是否符合要求,并确保所有关键信息都被涵盖。 </think> 美国联邦网络安全机构建议组织加强微软Intune设备管理系统的安全性,以应对伊朗关联的网络攻击威胁。攻击者通过入侵Intune系统清除了斯特瑞克公司20万台设备的数据。CISA和FBI敦促企业采用多因素认证、最小权限访问和双重审批机制,并采取其他安全措施保护Intune。同时,他们关闭了黑客网站并采取进一步行动应对威胁。 2026-3-19 16:0:51 Author: therecord.media(查看原文) 阅读量:4 收藏

Federal cybersecurity agencies urged organizations to better protect their deployment of a crucial Microsoft tool designed to manage all of the devices within a company’s network following an alleged Iran-connected cyberattack on a Michigan medical device company. 

The FBI and Cybersecurity and Infrastructure Security Agency (CISA) released an advisory on Wednesday night confirming their involvement in the response to the recent attack on Stryker — a large healthcare technology firm that has struggled for more than a week to recover from an attack where more than 200,000 company devices were wiped clean. 

The attackers did not use malware, instead breaking into a legitimate Microsoft device management system called Intune and wiping the company’s data that way. CISA urged companies that use Intune to follow Microsoft’s newly-released best practices and to “harden endpoint management system configurations.”

The advisories say Intune customers should use role-based access controls to assign the minimum permissions necessary to each role for completing day-to-day operations. All accounts should have multi-factor authentication and Microsoft Entra ID to “block unauthorized access to privileged actions in Microsoft Intune.”

“Set up policies that require a second administrative account’s approval to allow changes to sensitive or high-impact actions (such as device wiping),” CISA said. 

CISA provided links to several other Microsoft documents about security features that can be added to protect Intune. 

The hacking group behind the Stryker attack — named Handala — wiped thousands of devices, leaving company employees locked out of critical systems and struggling to continue working at factories across the U.S., Ireland, India and other countries. Some employees took to social media to complain that they had Intune installed on personal devices, meaning even their own non-company data had been wiped. 

CISA said it is “conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.”

A website connected to the Handala group was taken down by federal authorities this week. The FBI put a banner on the group’s website that said the FBI filed a seizure warrant after they determined the website "was used to conduct, facilitate, or support malicious cyber activities on behalf of, or in coordination with, a foreign state actor." 

"These activities may include unauthorized network intrusions, infrastructure targeting or other violations of U.S. law," the FBI wrote. The banner adds that the U.S. took over the website "to disrupt ongoing malicious cyber operations and prevent further exploitation." 

The action comes after Israeli officials claimed that several of the Iranian leaders behind Handala were recently killed in airstrikes.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/fbi-cisa-warn-of-microsoft-intune-risks-stryker
如有侵权请联系:admin#unsafe.sh