The U.S. Cybersecurity and Infrastructure Security Agency (CISA) performed simultaneous red team assessments on two critical infrastructure organizations, designated Organization A and Organization B. The assessments used similar attack methods, but the defensive outcomes varied significantly between the two entities. Both organizations experienced full domain-level compromise, with the red team also gaining access to sensitive business systems (SBSs) and cloud resources.
Organization A, a Government Services and Facilities Sector entity, did not detect any of the red team's activities. Initial access was gained through a web application using default credentials, leading to phishing emails and workstation compromise. Privilege escalation occurred by abusing a default Machine Account Quota and a misconfigured Active Directory Certificate Services (AD CS) template, similar to the Certighost exploit. The red team accessed sensitive business systems via cleartext credentials and exploited elevated permissions in cloud resources to monitor the security team's communications.
CISA attributed Organization A's failure to detect the compromise to several factors. Thousands of high-severity false-positive alerts obscured genuine threats. The organization operated multiple security operations centers (SOCs) and endpoint tools without shared visibility. Analysts lacked clear escalation procedures and had limited authority to act. A legitimate alert related to red team activity on a System Center Configuration Manager (SCCM) server was dismissed as a false positive because defenders could not identify the system's owner.
Organization B, a Water and Wastewater Systems Sector entity, experienced a full compromise but had different defensive responses compared to Organization A. The advisory, titled "A Tale of Two SOCs" and released on August 25, 2026, details these contrasting outcomes, emphasizing the impact of varying security postures and operational practices despite similar attack methodologies.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) conducted red team assessments on two critical infrastructure organizations, fully compromising both at the domain level and accessing sensitive systems. One organization failed to detect any of the red team's activities due to issues like excessive false positives and fragmented security operations. This highlights significant vulnerabilities in critical infrastructure defenses and the challenges in effective security monitoring.