mimile
Back to feed

CISA Red Team Compromises Two Critical Infrastructure Orgs, One Detects Nothing

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

CISA Red Team Compromises Two Critical Infrastructure Orgs, One Detects Nothing

CISA's red team compromised two critical infrastructure organizations at the domain level during simultaneous assessments, reaching sensitive business systems and cloud resources in both. Organization A, a Government Services and Facilities Sector entity, detected none of the activity, while Organization B, a Water and Wastewater Systems Sector entity, detected some but not all. The advisory, AA26-237A, was released on August 25, 2026.

Key Facts

  • CISA released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026.
  • Organization A is a Government Services and Facilities Sector organization; Organization B is a Water and Wastewater Systems Sector entity.
  • Against Organization A, the red team gained initial access via a web application with default credentials and sent phishing emails from an internal address, landing on four workstations.
  • Organization A did not detect any red team activity, with thousands of false-positive alerts obscuring genuine alerts.
  • CISA flagged default Machine Account Quota, misconfigured AD CS templates (ESC1), cleartext credentials, static cloud access keys, and over-permissioned Entra ID applications as main enablers.

Red Team Assessments

CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses. Both organizations were fully compromised at the domain level, and in both, the red team reached sensitive business systems and cloud resources. The advisory, tracked as AA26-237A and titled "A Tale of Two SOCs," was released on August 25, 2026.

Organization A Compromise

The red team gained initial access after identifying a web application with default credentials for several built-in accounts, which allowed it to send phishing emails from an internal address and land on four workstations. It escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Active Directory Certificate Services template, the same class of certificate-template abuse behind the Certighost exploit. The team accessed three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static AWS access keys set never to expire. In the cloud, it stole a Primary Refresh Token and abused Entra ID applications carrying elevated permissions to read the security team's email and check whether defenders were aware of the activity. Organization A did not detect any of it, with thousands of false-positive alerts from normal business operations obscuring the alerts the red team generated.

Detection Failures

Organization A ran multiple security operations centers and endpoint tools with no shared visibility between them. Analysts lacked escalation procedures and had limited authority to act. A real alert tied to red team activity on a System Center Configuration Manager server was dismissed as a false positive after defenders could not identify the system's owner. CISA flagged default Machine Account Quota, misconfigured AD CS templates (ESC1), cleartext credentials, static cloud access keys, and over-permissioned Entra ID applications as main enablers.

1 source

CISA Red Team Compromises Two Critical Infrastructure Orgs, One Detects Nothing