Your MDM Is a Weapon Now: Stryker Fleet Wipe, Weekend CISA Deadlines, and the Trust Infrastructure Collapse
The Stryker Attack Changes Your MDM Threat Model
On March 11, Iran-linked threat group Handala compromised Stryker's Microsoft Intune environment and executed a fleet-wide device wipe across 200,000+ systems and servers. The group's logo appeared on affected devices. Stryker's ordering and distribution systems remain disrupted as of March 20. The attackers also claim to have exfiltrated 50 terabytes of data before launching the wiper. Palo Alto's Unit 42 and Microsoft are actively investigating.
The most alarming detail: Handala weaponized Intune to remotely wipe employees' personal phones enrolled via BYOD, bricking devices and requiring carrier SIM reactivation. This is indistinguishable from normal admin operations unless Multi Admin Approval is enabled — which CISA's March 18 emergency guidance now mandates.
Your MDM is Tier-0 infrastructure. A compromised admin account doesn't just manage devices — it destroys them at fleet scale.
CISA's speed in responding — product-specific Intune guidance within 7 days — signals the intelligence community believes Intune misconfiguration is widespread, not unique to Stryker. The FBI seized Handala's websites March 19, but the group's destructive capability is demonstrated and their motivation is geopolitical (the ongoing Iran conflict), making deterrence unlikely.
Weekend Patch Deadlines You Cannot Miss
Two CISA KEV deadlines land this weekend, and a CVSS 10.0 demands immediate attention:
| CVE | Product | Detail | Deadline |
|---|---|---|---|
| CVE-2026-20963 | SharePoint Server | Unauth deserialization RCE — Microsoft said 'low likelihood' in January, now confirmed exploited | March 21 (Sat) |
| CVE-2026-20131 | Cisco FMC | Unauth Java RCE as root — exploited by Interlock ransomware since January 26 (37-day zero-day window) | March 22 (Sun) |
| CVE-2026-22557 | Ubiquiti UniFi | CVSS 10.0 path traversal → pre-auth account takeover (v10.1.85 and earlier) | No KEV yet — patch now |
The SharePoint flaw is a case study in why vendor exploitability assessments cannot be trusted for prioritization. Microsoft's January rating of "low likelihood" was wrong. Two months later, it's in CISA's KEV with a 3-day deadline. SharePoint 2007, 2010, and 2013 are also affected but receive no patches — these must be isolated or decommissioned.
The Cisco FMC vulnerability had a 37-day exploitation window before Cisco's March 4 patch. Amazon threat intelligence confirmed Interlock ransomware was exploiting it since January. If your FMC was internet-accessible at any point since January 26, conduct a forensic review, not just patching.
The Ubiquiti UniFi CVSS 10.0 is particularly dangerous because UniFi deployments proliferate in branch offices, guest networks, and labs — often as shadow IT. A companion NoSQL injection vulnerability (CVE-2026-22558, CVSS 7.7) enables privilege escalation after initial access.
What to do
Enforce Multi Admin Approval for all Intune device wipe/retire/reset actions and implement phishing-resistant MFA for all MDM admin accounts per CISA March 18 guidance
Apply January 2026 SharePoint security update for CVE-2026-20963 across all SharePoint Server 2016, 2019, and Subscription Edition instances before Saturday March 21 CISA deadline
Patch Ubiquiti UniFi Network Application above v10.1.85 and scan for shadow IT UniFi deployments in branch offices, labs, and guest networks
Verify Cisco FMC patched to March 4 update and conduct forensic review on any instance that was internet-accessible between January 26 and March 4 for Interlock ransomware indicators