Attack on Stryker’s Microsoft environment wiped employee devices without malware

2026-03-17T08:51:43Z57b4d1b6f5496a409bf8c53fb5b2c1c7de5101aec3ce0b23d1539d2313da2532
APTAppArmorCISADRILLAPPKnown Exploited VulnerabilityLaundry BearSignal account takeoverSteam malwareWing FTP Serverdata-theftdevice-wipehealthcare-breachprivilege-escalationransomwaresupply-chain

What happened

Multiple high-impact security incidents and disclosures were reported: a destructive intrusion against medical-technology vendor Stryker wiped tens of thousands of employee devices via its Microsoft environment (no malware reported) and many systems remain offline; CISA added an information-disclosure flaw in Wing FTP Server (CVE-2025-47813, CVSS 4.3) to its Known Exploited Vulnerabilities catalog; a Russia-linked APT deployed the DRILLAPP backdoor against Ukrainian targets using Microsoft Edge debugging for stealth (linked to Laundry Bear/PLUGGYAPE activity); the FBI opened an inquiry into a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
57b4d1b6f5496a409bf8c53fb5b2c1c7de5101aec3ce0b23d1539d2313da2532
Enrichment time
2026-03-17T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attack on Stryker’s Microsoft environment wiped employee devices without malware · Baitaphish