WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) CISA Urges Endpoint Management System Hardening Following Stryker Incident
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA Urges Endpoint Management System Hardening Following Stryker Incident

TLP:CLEAR

Author: Chase Snow

Created: Thursday, March 19, 2026 - 14:40

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: Yesterday, CISA issued an alert urging all organizations to strengthen endpoint management system configurations following malicious cyber activity targeting U.S. organizations, including the March 11 attack on Stryker Corporation, which affected their Microsoft environment.

Adversaries can abuse legitimate mobile and endpoint management tools. To reduce risk, CISA recommends that organizations implement Microsoft’s updated best practices for securing Microsoft Intune; these principles can apply to Intune and more broadly to other endpoint management software and similar platforms. Key actions include:

  • Applying least‑privilege administrative roles via RBAC.
  • Enforcing phishing‑resistant MFA and privileged‑access hygiene.
  • Requiring Multi‑Admin Approval for sensitive or high‑impact actions, such as device wipes, scripts, or configuration changes.

Analyst Note: This alert underscores the growing risk associated with the misuse of trusted administrative platforms rather than exploitation of traditional vulnerabilities (as was the case with Stryker). Endpoint management systems provide centralized control over devices, users, and configurations, making them high-value targets if compromised. Unauthorized access to these systems can enable rapid, large-scale actions, such as deploying malicious scripts or disrupting operations, across enterprise environments. Organizations benefit from prioritizing identity security, enforcing strict administrative controls, and validating changes to high-impact configurations. Increased attention to administrative access pathways, particularly those tied to cloud-based management platforms, is critical as threat actors continue to favor stealthy, legitimate credential-driven approaches over more detectable methods.

Original Source: https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization

Additional Reading:

  • Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach

Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 12

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar