CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

cisa-red-team-compromised-two-critical-infrastructure-orgs,-one-detected-nothing
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Swati KhandelwalAug 26, 2026Red Teaming / Security Operations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.

Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources.

The advisory, tracked as AA26-237A and titled “A Tale of Two SOCs,” was released on August 25, 2026. CISA identified the first target only as a Government Services and Facilities Sector organization, referred to as Organization A, and the second as a Water and Wastewater Systems Sector entity, referred to as Organization B.

“CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses,” the agency said in the advisory.

Against Organization A, the red team gained initial access after identifying a web application with default credentials for several built-in accounts, which allowed it to send phishing emails from an internal address and land on four workstations.

It then escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Active Directory Certificate Services (AD CS) template, the same class of certificate-template abuse behind a recently disclosed domain-takeover exploit called Certighost.

The team went on to access three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static Amazon Web Services (AWS) access keys set never to expire.

In the cloud, it stole a Primary Refresh Token and abused Entra ID applications carrying elevated permissions to read the security team’s email and check whether defenders were aware of the activity.

Organization A did not detect any of it. CISA said thousands of false-positive alerts from normal business operations, many rated at higher severity, obscured the alerts the red team generated, and that the organization ran multiple security operations centers (SOCs) and endpoint tools with no shared visibility between them.

Analysts also lacked escalation procedures and had limited authority to act, and a real alert tied to red team activity on a System Center Configuration Manager (SCCM) server was dismissed as a false positive after defenders could not identify the system’s owner.

CISA flagged the following weaknesses as the main enablers of the compromise –

  • Machine Account Quota left at the default, letting any domain user add machine accounts.
  • AD CS certificate templates were misconfigured, allowing certificate requests for any user (ESC1).
  • Cleartext credentials for service and database accounts stored on reachable systems.
  • Static cloud access keys set never to expire, with no token revocation in place.
  • Over-permissioned applications in Entra ID able to read mail across all users.

Organization B, running the same style of attack against it, told a different story. Its SOC detected the initial phishing payloads as each executed and isolated the affected workstations within 2 to 20 minutes, cutting off command-and-control (C2) communications before the intrusion could spread.

Because that foothold was severed, CISA’s trusted agents at the organization executed a red team payload on a designated non-privileged host to replicate the access the team would otherwise have obtained, shifting the engagement to an assume-breach model.

From there, the team found the same underlying problems, including cleartext credentials for a domain service account in an SCCM configuration file that carried rights over a domain controller, which it used to run a DCSync attack and retrieve the krbtgt secret.

The team also reached a bastion host in Organization B’s operational technology (OT) demilitarized zone, but the host blocked outbound internet access, so no C2 channel was established, and the team did not enter the OT systems themselves.

CISA attributed the gap between the two outcomes to the people and processes operating the tools, rather than the tools themselves.

“Detection tools are only as effective as the people, processes, and procedures supporting them,” the agency said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Leave a Reply

Your email address will not be published. Required fields are marked *