Live data from Hacker News

Iran-backed hackers claim wiper attack on medtech firm Stryker

krebsonsecurity.com

71–80 of 342 posts

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#71

So gain access to a machine that can ask microsoft intune to eviscerate the company, ask it to do so, done. Bit of a shame all the machines had that installed really. Reminds me of crowdstrike.

The company should have known better than to trust their IT infrastructure to Microslop. This is their own fault.

[flagged]

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#72

Does InTune have some sort of check that goes "if over 1% of devices are wiped within a certain timeframe, stop all new device wipe requests"? Seems like it should be a feature, especially if these kinda attacks pick up.

Everything is obvious in hindsight And to be clear, SCCM and Intune is a gun. MS will not stop you from blowing your foot off with the gun. Remember https://www.itprotoday.com/windows-7/aggressive-configmgr-ba... ? >During TechEd 2014, Emory University's IT department prepared and deployed Windows 7 upgrades to the campuses computers. If you've worked with ConfigMgr at all, you know that there are checks-and-balances…

That ANY kind of config change should be rate-limited has been pretty obvious and hammered on in SRE manuals for at least 10 years.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#73
post #72

Earlier quoted context omitted.

Everything is obvious in hindsight And to be clear, SCCM and Intune is a gun. MS will not stop you from blowing your foot off with the gun. Remember https://www.itprotoday.com/windows-7/aggressive-configmgr-ba... ? >During TechEd 2014, Emory University's IT department prepared and deployed Windows 7 upgrades to the campuses computers. If you've worked with ConfigMgr at all, you know that there are checks-and-balances…

That ANY kind of config change should be rate-limited has been pretty obvious and hammered on in SRE manuals for at least 10 years.

And who sets the limits? MS? What if a company WANTS to wipe their entire fleet?

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#74
post #38
post #27

Never add your personal device to a companies MDM…

Never use your personal device for work, you wanted to say, probably.

The only maybe grey area is to only us it as authenticator. But yes even then the company needs to provide this, a cheap phone works.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#75

Earlier quoted context omitted.

[flagged]

I have no idea why you would assume Israel had to resort to extortion to get Trump to help them bomb Iran. We bombed Venezuela a few weeks ago, no extortion required. It's far more likely he was did it because Hegseth thought it would be more manly or something more ego driven than extortion. More likely it's just another example of flooding the zone to forget about the Epstein files and the stagnating economy

I am thinking the theories are true because of the must larger negative repercussions of that action.

They are strengthening the regime (US intelligence services were aware of that before the attack and had informed the president), they are destabilizing all their oil producers, they are risking great economic cost..

It only makes sense if indeed they either extorted him, or if he is indeed demented / deranged.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#76

Does InTune have some sort of check that goes "if over 1% of devices are wiped within a certain timeframe, stop all new device wipe requests"? Seems like it should be a feature, especially if these kinda attacks pick up.

This raises the question: Are mass layoffs less frequent than a company's MS administrator account getting hacked?

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#77

Earlier quoted context omitted.

[flagged]

See, here is what I've observed. I don't expect to change your POVs. Nevertheless... The issue started when Israel was ready to have recognition from Saudi Arabia on their statehood. This would make Hamas irrelevant. And puts Sunnis (Iran) lesser recognised. Meanwhile Shia's (Saudi) will become the defacto in the Muslim world and half of Muslim world would either tolerate or be OK with Israel. Hamas attack on Israel…

>You need to understand, there was good period of peace between Israel & Palestine until Oct 7.

Yes, in the year before Oct 7. alone Israel army had only killed about 40 Palestinian children (34 alone between Jan and Nov 2022).

Not to mention Iran has been a target since 2001: https://www.youtube.com/watch?v=FNt7s_Wed_4 - if not since 1953 (their 1979 changes being a response to the 1950s western invervention that installed a dictatorship), if not since forever:

https://en.wikipedia.org/wiki/Great_Game

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#78
post #24

Earlier quoted context omitted.

Well, time to dust off anti-drone defense systems. Today on NPR they talked that Iran plans to launch drones from ships into California. https://www.10news.com/news/local-news/authorities-warn-of-p... Fox News drone expert: https://nypost.com/2026/03/11/us-news/iran-could-use-drones-...

Sounds like justification for a false flag operation by the US government. How would they transport these massive things and launch them on a different continent? That, or the US is trying to justify that this illegal war is on their doorstep and need to expand their terror.

The drones Iran are using are actually relatively small, you can fit 5 of them into a medium sized truck and they can launch in-situ, which is how they've been using them in ground operations. Doesn't seem that much of a stretch to put a bunch of them into shipping containers.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#79

Earlier quoted context omitted.

I have no idea why you would assume Israel had to resort to extortion to get Trump to help them bomb Iran. We bombed Venezuela a few weeks ago, no extortion required. It's far more likely he was did it because Hegseth thought it would be more manly or something more ego driven than extortion. More likely it's just another example of flooding the zone to forget about the Epstein files and the stagnating economy

I am thinking the theories are true because of the must larger negative repercussions of that action. They are strengthening the regime (US intelligence services were aware of that before the attack and had informed the president), they are destabilizing all their oil producers, they are risking great economic cost.. It only makes sense if indeed they either extorted him, or if he is indeed demented / deranged.

Or he's just a manchild who likes doing things that he thinks will make him look strong.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#80

Earlier quoted context omitted.

See, here is what I've observed. I don't expect to change your POVs. Nevertheless... The issue started when Israel was ready to have recognition from Saudi Arabia on their statehood. This would make Hamas irrelevant. And puts Sunnis (Iran) lesser recognised. Meanwhile Shia's (Saudi) will become the defacto in the Muslim world and half of Muslim world would either tolerate or be OK with Israel. Hamas attack on Israel…

> You need to understand, there was good period of peace between Israel & Palestine until Oct 7. What a disgusting and patronizing rewriting of history. This "peace" was enforced by ongoing occupation of Palestine and abuse of the people living there.

[flagged]
Post reply on HN