Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The Hacker News by The Hacker News
August 26, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalAug 26, 2026Red Teaming / Security Operations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.

Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources.

The advisory, tracked as AA26-237A and titled “A Tale of Two SOCs,” was released on August 25, 2026. CISA identified the first target only as a Government Services and Facilities Sector organization, referred to as Organization A, and the second as a Water and Wastewater Systems Sector entity, referred to as Organization B.

“CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses,” the agency said in the advisory.

Against Organization A, the red team gained initial access after identifying a web application with default credentials for several built-in accounts, which allowed it to send phishing emails from an internal address and land on four workstations.

It then escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Active Directory Certificate Services (AD CS) template, the same class of certificate-template abuse behind a recently disclosed domain-takeover exploit called Certighost.

The team went on to access three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static Amazon Web Services (AWS) access keys set never to expire.

In the cloud, it stole a Primary Refresh Token and abused Entra ID applications carrying elevated permissions to read the security team’s email and check whether defenders were aware of the activity.

Organization A did not detect any of it. CISA said thousands of false-positive alerts from normal business operations, many rated at higher severity, obscured the alerts the red team generated, and that the organization ran multiple security operations centers (SOCs) and endpoint tools with no shared visibility between them.

Analysts also lacked escalation procedures and had limited authority to act, and a real alert tied to red team activity on a System Center Configuration Manager (SCCM) server was dismissed as a false positive after defenders could not identify the system’s owner.

CISA flagged the following weaknesses as the main enablers of the compromise –

  • Machine Account Quota left at the default, letting any domain user add machine accounts.
  • AD CS certificate templates were misconfigured, allowing certificate requests for any user (ESC1).
  • Cleartext credentials for service and database accounts stored on reachable systems.
  • Static cloud access keys set never to expire, with no token revocation in place.
  • Over-permissioned applications in Entra ID able to read mail across all users.

Organization B, running the same style of attack against it, told a different story. Its SOC detected the initial phishing payloads as each executed and isolated the affected workstations within 2 to 20 minutes, cutting off command-and-control (C2) communications before the intrusion could spread.

Because that foothold was severed, CISA’s trusted agents at the organization executed a red team payload on a designated non-privileged host to replicate the access the team would otherwise have obtained, shifting the engagement to an assume-breach model.

From there, the team found the same underlying problems, including cleartext credentials for a domain service account in an SCCM configuration file that carried rights over a domain controller, which it used to run a DCSync attack and retrieve the krbtgt secret.

The team also reached a bastion host in Organization B’s operational technology (OT) demilitarized zone, but the host blocked outbound internet access, so no C2 channel was established, and the team did not enter the OT systems themselves.

CISA attributed the gap between the two outcomes to the people and processes operating the tools, rather than the tools themselves.

“Detection tools are only as effective as the people, processes, and procedures supporting them,” the agency said.



Source link

The Hacker News

The Hacker News

Next Post

Ninkear präsentiert auf der IFA 2026 KI-fähige Mini-PCs und leistungsstarke Laptops

Recommended.

Coveo Reports Fourth Quarter and Fiscal 2026 Financial Results

Coveo Reports Fourth Quarter and Fiscal 2026 Financial Results

May 27, 2026
The9 Announces JV Acquisition to Operate Proprietary Mobile Games Ultraman: Hero Beyond Time and Glory All Stars

The9 Announces JV Acquisition to Operate Proprietary Mobile Games Ultraman: Hero Beyond Time and Glory All Stars

September 19, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio