Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
August 25, 2026
AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats
August 25, 2026
SynkLoader Malware Impersonates IT Support on Microsoft Teams
August 25, 2026
Home/CyberSecurity News/CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
CyberSecurity News

CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps

Key Takeaways CISA red team operations successfully breached two critical infrastructure organizations, exposing significant security vulnerabilities. The same attack techniques yielded vastly...

Sarah simpson
Sarah simpson
August 25, 2026 4 Min Read
2 0

Key Takeaways

  • CISA red team operations successfully breached two critical infrastructure organizations, exposing significant security vulnerabilities.
  • The same attack techniques yielded vastly different outcomes, highlighting the critical role of human analysts and robust security processes over mere technological investment.
  • One organization (Organization A) suffered a complete compromise without detection, including keylogger deployment and access to SOC staff emails.
  • The other (Organization B) rapidly detected and contained initial intrusions, demonstrating effective layered defenses and human response.
  • Key vulnerabilities exploited included Active Directory misconfigurations (e.g., Machine Account Quota, AD Certificate Services templates) and inadequate incident response procedures.

CISA Red Team Uncovers Major Security Gaps in Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to critical infrastructure operators, revealing that even well-funded security systems can fail without skilled analysts and robust operational procedures. A new CISA advisory details parallel red team engagements against two distinct critical infrastructure entities, showcasing how identical attack methodologies led to dramatically divergent security outcomes.

Table Of Content

  • Key Takeaways
  • CISA Red Team Uncovers Major Security Gaps in Critical Infrastructure
  • Breach Successes and Failures
  • Operational Dysfunction vs. Empowered Response
  • What You Should Do

CISA’s report, titled “A Tale of Two SOCs,” outlines two red team exercises. One targeted an organization within the Government Services and Facilities Sector (Organization A), while the other focused on a Water and Wastewater Systems Sector entity (Organization B). In both simulated attacks, CISA’s operators initiated their breach with phishing campaigns, subsequently exploiting common Active Directory misconfigurations, such as default Machine Account Quotas and improperly configured Active Directory Certificate Services templates, to escalate privileges and move laterally within the networks.

Breach Successes and Failures

At Organization A, the red team achieved a comprehensive compromise. They successfully gained elevated domain privileges, infiltrated sensitive business systems, and accessed cloud resources, all without triggering any alerts. The attackers even managed to read SOC staff emails and deploy keyloggers on the defenders’ own machines, demonstrating a complete breakdown in detection and response capabilities.

Organization B, however, presented a different scenario. Its Security Operations Center (SOC) demonstrated remarkable agility, isolating compromised workstations within a rapid timeframe of 2 to 20 minutes following the execution of the initial phishing payload. This swift action effectively severed command-and-control communications, preventing the intrusion from spreading further into the network.

Due to Organization B’s effective initial containment, CISA shifted its approach to an “assume breach” model. Under this scenario, trusted internal agents granted the red team access equivalent to what they would have achieved had the initial phishing attempt gone undetected. From this advanced starting point, the red team once again escalated privileges by exploiting the same Machine Account Quota vulnerability. They further harvested cleartext credentials from a System Center Configuration Manager file and executed DCSync attacks to obtain domain controller credentials, including the highly sensitive krbtgt account, which can be used to forge Golden Tickets.

Despite this deep level of assumed compromise, Organization B’s defenders continued to exhibit resilience. They successfully isolated a compromised bastion host located in the operational technology demilitarized zone and blocked a suspicious Azure sign-in attempt that was flagged by Microsoft’s automated alerting systems. This demonstrated that even after a significant breach, layered detection mechanisms and active human intervention continued to provide critical defensive capabilities.

Operational Dysfunction vs. Empowered Response

CISA attributed Organization A’s profound security blind spots not to a lack of security tools, but to significant operational dysfunction. The organization operated multiple SOCs and utilized various Endpoint Detection and Response (EDR) platforms without adequate cross-team communication. Furthermore, thousands of false-positive alerts generated by routine business activities effectively buried genuine indicators of compromise.

Analysts at Organization A also lacked standardized operating procedures for escalating suspicious activity and possessed limited authority to act. Consequently, legitimate alerts, including one directly tied to red team activity on an SCCM server, were erroneously dismissed as false positives because defenders could not readily identify the system owner.

The advisory’s central takeaway underscores that the effectiveness of detection tooling is intrinsically linked to the human expertise and robust processes supporting it. CISA is strongly urging critical infrastructure operators to address common Active Directory weaknesses, such as unrestricted Machine Account Quotas and ESC1-vulnerable certificate templates. Additionally, they recommend enforcing credential expiration policies for service and cloud accounts and adopting Conditional Access for workload identities to mitigate risks associated with application permissions.

Crucially, organizations must establish documented escalation procedures, foster cross-team visibility, and empower their analysts. Organization B’s success was ultimately attributed to its rapid triage and decisive isolation capabilities, rather than reliance on any single security product.

What You Should Do

  • Address Active Directory Misconfigurations: Immediately review and remediate common Active Directory weaknesses, including unrestricted Machine Account Quotas and vulnerable Active Directory Certificate Services (AD CS) templates (e.g., ESC1).
  • Implement Strong Credential Management: Enforce credential expiration for all service accounts and cloud accounts. Implement multi-factor authentication (MFA) across all critical systems.
  • Adopt Conditional Access: Utilize Conditional Access policies for workload identities to enhance security around application permissions and access.
  • Develop and Enforce Incident Response Procedures: Establish clear, documented standard operating procedures (SOPs) for detecting, escalating, and responding to suspicious activity. Ensure these procedures are regularly tested and updated.
  • Empower Your SOC Analysts: Provide analysts with the necessary training, tools, and authority to investigate and act decisively on security alerts. Foster a culture of proactive threat hunting and rapid response.
  • Improve Cross-Team Communication: Break down silos between security teams and other IT departments to ensure a unified view of the security landscape and efficient incident resolution.
  • Reduce Alert Fatigue: Optimize security tools to minimize false positives and ensure that genuine indicators of compromise are not overlooked. Prioritize alerts based on severity and potential impact.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachphishingSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification
August 25, 2026
ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks
August 25, 2026
Fake Microsoft Security Scan Tricks Users into Removing Antivirus
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us