← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

CISA Red Team Fully Compromises Two Critical Infrastructure Organizations; One Undetected

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA red team fully compromised two critical infrastructure organizations.
  • One organization detected none of the red team's activities.
  • Compromises involved domain-level access and sensitive business systems.
  • Issues included default credentials, misconfigurations, and poor alert management.

CISA Red Team Assessments

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) performed simultaneous red team assessments on two critical infrastructure organizations, designated Organization A and Organization B. The assessments used similar attack methods, but the defensive outcomes varied significantly between the two entities. Both organizations experienced full domain-level compromise, with the red team also gaining access to sensitive business systems (SBSs) and cloud resources.

Organization A: Complete Lack of Detection

Organization A, a Government Services and Facilities Sector entity, did not detect any of the red team's activities. Initial access was gained through a web application using default credentials, leading to phishing emails and workstation compromise. Privilege escalation occurred by abusing a default Machine Account Quota and a misconfigured Active Directory Certificate Services (AD CS) template, similar to the Certighost exploit. The red team accessed sensitive business systems via cleartext credentials and exploited elevated permissions in cloud resources to monitor the security team's communications.

Defensive Failures at Organization A

CISA attributed Organization A's failure to detect the compromise to several factors. Thousands of high-severity false-positive alerts obscured genuine threats. The organization operated multiple security operations centers (SOCs) and endpoint tools without shared visibility. Analysts lacked clear escalation procedures and had limited authority to act. A legitimate alert related to red team activity on a System Center Configuration Manager (SCCM) server was dismissed as a false positive because defenders could not identify the system's owner.

Organization B: Different Outcomes

Organization B, a Water and Wastewater Systems Sector entity, experienced a full compromise but had different defensive responses compared to Organization A. The advisory, titled "A Tale of Two SOCs" and released on August 25, 2026, details these contrasting outcomes, emphasizing the impact of varying security postures and operational practices despite similar attack methodologies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) conducted red team assessments on two critical infrastructure organizations, fully compromising both at the domain level and accessing sensitive systems. One organization failed to detect any of the red team's activities due to issues like excessive false positives and fragmented security operations. This highlights significant vulnerabilities in critical infrastructure defenses and the challenges in effective security monitoring.