[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwj2QLAhJf7_v6-cTmzWUAF__mK7PEGFls2Fuwnl7iNQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"5108bdd2-bed2-4d09-b3e8-b265e14e45db","credential-theft-leads-to-cloud-infrastructure-compromise","ca2cfde5-5fc1-4584-9cb8-3efca01cb837","Credential Theft Leads to Cloud Infrastructure Compromise","Stryker fell victim to an Iran-linked cyberattack where attackers obtained legitimate credentials through infostealer malware and used them to abuse the company's Microsoft Intune cloud management platform. The attackers deployed custom malicious files to hide their activities while maintaining persistent access to global operations. This incident demonstrates how credential compromise can lead to widespread infrastructure access, even when attackers don't deploy traditional ransomware or wiper malware. The attack's success hinged on the initial credential theft, which then provided a pathway to cloud-based management systems.","**Immediate actions:**\n- This attack could have been prevented through multi-layered security controls including robust endpoint protection to block infostealer malware, mandatory multi-factor authentication (MFA) for all cloud services especially privileged platforms like Microsoft Intune, and implementation of zero-trust access principles\n\n**Long-term improvements:**\n- Regular security awareness training should educate employees about phishing and malware threats that lead to credential theft\n\n**Detection measures:**\n- privileged access management (PAM) solutions should be deployed to monitor and control access to critical cloud infrastructure, with continuous monitoring for unusual access patterns or unauthorized activities in cloud management platforms",[12,13,14,15,16,17,18],"CIS Control 6","CIS Control 8","NIST AC-2","NIST AC-3","NIST IA-2","NIST SI-3","NIST AT-2","published","2026-03-24T18:07:25.459673+00:00","2026-03-24T18:07:25.348+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fwww.securityweek.com\u002Fstryker-says-malicious-file-found-during-probe-into-iran-linked-attack\u002F","stryker-says-malicious-file-found-during-probe-into-iran-linked-attack","Stryker Says Malicious File Found During Probe Into Iran-Linked Attack",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":34,"name":35,"slug":36,"description":37,"color":38},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[40],{"id":41,"date":42,"edition":43,"title":44,"audio_url":45},"751a8a85-5b7c-45b1-8049-097dc39b86b1","2026-03-24","afternoon","ThreatNoir Afternoon Brief — March 24","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-03-24\u002Fthreatnoir-afternoon-brief-2026-03-24.mp3"]