Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Red Team Exploits Vulnerabilities in Critical Infrastructure Organizations




A recent incident carried out by the Cybersecurity and Infrastructure Security Agency (CISA) red team has highlighted the vulnerabilities in critical infrastructure organizations. The red team successfully compromised two organizations, demonstrating how easily attackers can gain access to sensitive systems. The incident emphasizes the importance of prioritizing cybersecurity and taking proactive steps to improve security posture. By understanding the vulnerabilities that have been exploited by attackers, organizations can take steps to prevent similar incidents in the future.

  • The Cybersecurity and Infrastructure Security Agency (CISA) announced that its red team compromised two critical infrastructure organizations, highlighting vulnerabilities in their systems.
  • The red team used comparable techniques against both organizations, including exploiting default credentials and sending phishing emails, but the outcome differed in terms of detection and response.
  • One organization failed to detect or contain the activity, while the other rapidly identified the initial compromise attempts and isolated affected systems.
  • The vulnerabilities exploited by the red team were related to cloud security, particularly the lack of Conditional Access for workload identities.
  • CISA recommends several practical steps to improve security, including hardening Active Directory Certificate Services, enabling Conditional Access, and creating procedures to revoke tokens.
  • The incident highlights the importance of having well-defined baselines, alert filtering, and clear authority for SOC staff to effectively contain and resolve incidents.



  • The Cybersecurity and Infrastructure Security Agency (CISA) has announced that its red team has successfully compromised two critical infrastructure organizations, highlighting the vulnerabilities in their respective systems. The red team assessments were conducted simultaneously and revealed different defensive outcomes, with one organization failing to detect or contain the activity, while the other rapidly identified the initial compromise attempts and isolated affected systems.

    The red team used comparable techniques against both organizations, including exploiting default credentials, sending phishing emails from a trusted internal address, and gaining access to sensitive business systems. However, the difference in outcome was entirely about detection and response, not the sophistication of the attack.

    The first organization, a Government Services and Facilities Sector entity, failed to detect or contain the activity. The red team found a web application that still used default credentials, which they used to send phishing emails from a trusted internal address. They then exploited a misconfigured Active Directory Certificate Services template with the ESC1 flaw, allowing a low-privileged user to request certificates for other users, including administrators. This allowed the red team to reach all the targeted sensitive business systems without anyone noticing.

    In contrast, the second organization, a Water and Wastewater Systems Sector entity, rapidly identified the initial compromise attempts and isolated affected systems. The red team found a password stored in plain text inside an XML file on an SCCM distribution point, which they used to gain powerful rights over a domain controller. They also discovered a path into the OT network through RDP files pointing to a bastion host.

    Both organizations had the same cloud security problem: neither had enabled Conditional Access for workload identities. The red team used this gap in both organizations to access emails across the companies. In the first organization, the red team also found AWS IAM credentials stored in users' home directories with no expiration date, which could remain valid indefinitely.

    CISA's red team used various techniques to gain access to the systems, including using keyloggers and screenshot capture on SOC workstations to ensure that nothing was coming from the organization. The agency recommends several practical steps to improve security, including hardening ADCS, enabling Conditional Access for workload identities, and creating procedures to revoke tokens.

    The full advisory also maps each red team technique to its MITRE ATT&CK identifier and compares how well the two organizations detected the different stages of the attacks. The incident highlights the importance of having well-defined baselines and alert filtering, as well as the need for organizations to tune their alerts to highlight anomalies and filter out normal business activity.

    In addition, CISA emphasizes the importance of SOC staff having clear authority unhindered by bureaucracy to effectively contain and resolve incidents. The agency also notes that detection tools are only as effective as the people, processes, and procedures supporting them.

    The incident is a stark reminder of the need for critical infrastructure organizations to prioritize their cybersecurity posture. By understanding the vulnerabilities that have been exploited by attackers, organizations can take steps to improve their security and prevent similar incidents in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Red-Team-Exploits-Vulnerabilities-in-Critical-Infrastructure-Organizations-ehn.shtml

  • https://securityaffairs.com/197901/hacking/cisa-red-team-fully-compromised-two-critical-infrastructure-orgs.html


  • Published: Wed Aug 26 20:39:28 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us