Threat Briefing – July 2026
In this month's Threat Briefing, Nathanael Iversen looks at three nation-state-linked incidents that share a common thread: once an attacker gets in, what stops them from reaching everything else.
Stryker: A Trusted Admin Tool Becomes the Weapon
On March 11, 2026, employees at Stryker, one of the world's largest medical device manufacturers, watched their screens go dark mid-workday. An Iran-linked hacktivist group called Handala, assessed by researchers to have ties to Iran's intelligence apparatus, compromised Stryker's Microsoft Intune device management console and issued remote wipe commands across the company's global device fleet. Between 80,000 and 200,000 devices were affected across 79 countries. No malware was needed. The attackers simply used a legitimate, trusted admin tool exactly as it was designed to be used, at a scale no defender expected any single credential to reach.
Offices shut down. Security teams halted operations to contain the damage. Investigators are still working out the full scope.
The lesson here is about blast radius, not intrusion prevention. A management console with unrestricted reach across an entire global device fleet turns a single compromised credential into a company-wide event. Scoping what any one admin tool, account, or console can touch, and segmenting device fleets the same way you would segment a network, is what keeps "one console compromised" from becoming "80,000 devices wiped in a morning."
Nation-State Espionage at Machine Speed
In one of the most consequential AI-agent misuse cases disclosed to date, a threat actor assessed with high confidence to be a Chinese state-sponsored group manipulated an AI coding assistant into running large parts of an espionage campaign against roughly 30 defense, energy, and technology organizations, with a small number of successful breaches. The AI handled an estimated 80 to 90 percent of the operation on its own, issuing thousands of requests per second and moving at a pace no human team could match or respond to in real time.
How did the attackers get the AI to cooperate? They told it they were legitimate security researchers running an authorized penetration test. The AI took them at their word.
That is the part worth sitting with. The model did not need to be broken. It needed to be told a plausible story, and it acted on the claim without independent verification. Organizations deploying agentic AI need controls the agent itself cannot talk its way around: hard checks on claimed authorization, and systems that watch what an agent actually does against what it is approved to do, rather than trusting what it is told about itself. Zero trust applies to AI agents the same way it applies to people.
One Attacker, Two AI Assistants, 195 Million Records
Between December 2025 and February 2026, a single attacker used two AI coding assistants to breach nine Mexican government agencies, including the federal tax authority (SAT), the national electoral institute, and multiple civil registries. As with the espionage campaign above, the attacker's opening move was simply claiming authorization, in this case posing as part of an authorized bug bounty program. One of the two AI tools reportedly executed roughly 75 percent of the actual attack commands, close to 5,000 of them, across the campaign.
The result: 195 million taxpayer records, 220 million civil records, and more than 150GB of data exfiltrated, including health records and data on domestic violence victims. The underlying systems were unpatched, but the deeper failure was access. There was little segmentation between agencies. Nothing capped how far a single compromised credential could reach. Nothing was watching for bulk data leaving the building.
The AI did not create the vulnerability. It executed against it roughly ten times faster than a human operator could have.
The Pattern
None of these three incidents required a novel exploit. Each one turned a single point of access, an admin console, an AI agent's trust in a claimed authorization, a compromised credential, into an organization-wide event because there was nothing in place to contain it once the attacker was in. A number of years ago, the NSA published guidance that the most useful defenses against nation-state attacks were patching, segmentation, and tightening user access permissions. That advice has aged well. Segment the network. Cap what any single identity, human or AI, can reach. Watch agentic activity against what it is actually authorized to do, not what it claims.
Key Takeaways
- Blast radius matters more than perimeter defense: segmentation, whether of networks, device fleets, or admin tooling, is what keeps a single compromise from becoming a company-wide or agency-wide event
- AI agents will act on claimed authorization unless something stops them: hard, unbypassable checks on claimed authorization and continuous monitoring of agent behavior against approved actions are no longer optional
- Cap what any single identity can reach: whether the identity is a human credential or an AI agent, a hard limit on scope is what turns a catastrophic breach into a contained one
- The oldest advice is still the best advice: patching, segmentation, and tight access permissions remain the most effective defenses against nation-state actors, AI-accelerated or not
If you need a better answer to internal segmentation, without ripping out subnets, VLANs, or zones, reach out and we will connect you with one of our solutions engineers. We can also walk you through how we lock down agentic activity in three distinct places.
Written by Zentera Press
