READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Hackers Wiped 200,000 Devices at Medical Giant Stryker by Hijacking Microsoft's Own Admin Tools, Security Firm Says

Hackers Wiped 200,000 Devices at Medical Giant Stryker by Hijacking Microsoft's Own Admin Tools, Security Firm Says
An Iranian-aligned hacking group allegedly turned Microsoft's Intune device-management console into a weapon against Stryker, wiping over 200,000 devices, according to Microsoft 365 security vendor CoreView. The bigger story: enterprise AI has three layers of attack surface, and most companies are only guarding the front door while agents, plugins, and admin consoles sit wide open behind it.

A single compromised admin login. That's reportedly all it took for attackers to wipe more than 200,000 devices at Stryker, the medical technology company, according to Microsoft 365 security vendor CoreView.

CoreView says an Iranian-aligned threat group broke into Stryker by compromising admin credentials, then abused Microsoft's own Intune device-management console, the tool built to protect endpoints, and used it to erase devices across the company's global fleet. No government agency or independent outlet has confirmed the attribution or the device count in these sources. That claim comes from a vendor whose business is selling Microsoft 365 configuration monitoring, so treat the specifics as reported by CoreView, not as independently verified fact.

Even with that caveat, the mechanism is not in dispute: a device-management platform meant to secure endpoints became the tool that destroyed them once someone got the admin keys. CoreView argues that the configuration layer of a Microsoft 365 tenant, not just the login screen, now needs constant monitoring. Their pitch is that multi-factor authentication is still non-negotiable, but AI-accelerated attacks are already finding ways around it, so companies need a known-good configuration baseline, real-time drift detection, and a fast rollback plan. That's also, unsurprisingly, exactly what CoreView sells.

The Three Layers Nobody Is Watching Together

Tech Times lays out a useful framework for why incidents like this keep slipping through: the enterprise AI attack surface has three layers, and most security teams only watch one.

Layer one is the access layer, the traffic to ChatGPT, Gemini, Copilot, and other AI tools that flows through a company's proxies, firewalls, and cloud access brokers. This is the layer security teams know best because they can write a policy that blocks it. But Tech Times points out the obvious hole: even a fully staffed cloud access broker cannot decrypt a conversation flowing to a legitimate AI domain over HTTPS. A prompt carrying a company's customer database looks identical to any other encrypted session.

Layer two is orchestration, the plugins, "skills" frameworks, and MCP-style servers that let an AI agent actually call APIs, run jobs, or touch internal systems. Tech Times calls this a maze: over-scoped tools that can reach too many systems, weak authentication between an agent and the server it's calling, and thin logging of what got called and why.

Layer three, the agent and data layer, is where autonomous decision-making happens. SiliconANGLE's coverage of enterprises building "AI factories" addresses this directly. Dave Vellante, chief analyst at theCUBE Research, describes it as a world where "data is not static, bounded or easily classified," and where agents "increasingly act autonomously, interacting with enterprise systems, executing workflows and making decisions with limited, or sometimes no, human intervention."

Dell's Mukund Khatri, fellow and vice president of systems architecture, frames the stakes bluntly: a large language model can give a wrong answer, but an agent can take the wrong action, and that's more damaging. Dell's Steve Kenniston, senior cybersecurity evangelist, says AI introduces new attack surfaces at every layer, from model inferencing to identity management to prompt injection.

The Tool Market Is Consolidating, Not Converging

Nudge Security's comparison of ten AI security platforms for 2026 makes a fair point: none of the ten do all three jobs of AI security (discovery, runtime protection, and model security) at once. If a company buys one tool thinking it covers the whole attack surface, it's wrong.

The market itself has been consolidating. Palo Alto Networks folded Protect AI's technology into its Prisma AIRS platform in July 2025. Cato Networks acquired Aim Security two months later. Check Point has since acquired Lakera as well. Nudge Security also notes the EU AI Act is pushing governance platforms toward audit-ready evidence, like model inventories and compliance documentation, ahead of enforcement.

A reasonable skeptic would say this whole conversation is being driven by vendors with something to sell. CoreView sells configuration monitoring. Nudge Security sells AI and SaaS discovery. Every vendor in this space has an incentive to declare the threat larger than it is. That's a fair read of the incentives, and readers should apply it. But the underlying facts stand: agents now act on live data with limited human review, plugin architectures often lack basic authentication controls, and a single admin account reportedly opened the door to a 200,000-device wipe. They require asking a narrower question: who at your company can see what an AI agent actually did last week, and can they prove it?

Stryker has not issued a public statement on the incident in these sources, and no regulatory filing or breach disclosure has been cited. Whether Stryker confirms the attack, and whether any government agency formally attributes it to an Iranian-aligned group, remains an open question.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
Tech TimesThe Enterprise AI Attack Surface Has Three Layers. Most Security Teams Are Only Watching One - Tech Times
unknown
coreviewThe New AI Threats Facing Microsoft 365 Tenants: What Security Teams Need to Watch
unknown
nudgesecurityBest AI Security Tools Compared For 2026
unknown
SiliconANGLEAI attack surface reshapes enterprise security