Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA's Red Team Exercises: A Cautionary Tale of Vulnerabilities in Critical Infrastructure




CISA's Red Team Exercises: A Cautionary Tale of Vulnerabilities in Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory detailing the findings of two simultaneous red team assessments conducted against two critical infrastructure organizations. The exercise revealed that despite employing similar tradecraft, the two organizations exhibited vastly different defensive responses to the simulated attack. The advisory highlights the importance of robust security controls, regular security testing, and employee training in preventing and responding to cyber threats. Readers are encouraged to review the advisory for further information on the vulnerabilities and mitigation strategies.

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) conducted a red team assessment against two critical infrastructure organizations, highlighting vastly different defensive responses to a simulated attack.
  • Organization A was breached due to default credentials, misconfigured Active Directory Certificate Services, and cleartext credentials, while Organization B was able to detect and isolate the attack within minutes.
  • The gap between the two outcomes was attributed to the people and processes operating the tools, not the tools themselves.
  • Key vulnerabilities identified in the breach included: Machine Account Quota left at default, misconfigured AD CS certificate templates, cleartext credentials, static cloud access keys, and over-permissioned applications.
  • CISA emphasizes the importance of robust security controls, regular security testing, and employee training in preventing and responding to cyber threats.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently released a critical advisory detailing the findings of two simultaneous red team assessments conducted against two critical infrastructure organizations. The exercise, tracked as AA26-237A and titled "A Tale of Two SOCs," revealed that despite employing similar tradecraft, the two organizations exhibited vastly different defensive responses to the simulated attack.

    The first target, referred to as Organization A, was a Government Services and Facilities Sector organization. The red team gained initial access by identifying a web application with default credentials for several built-in accounts, which allowed them to send phishing emails from an internal address and land on four workstations. The team then escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Active Directory Certificate Services (AD CS) template. The team went on to access three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static Amazon Web Services (AWS) access keys set never to expire.

    In contrast, the second target, referred to as Organization B, a Water and Wastewater Systems Sector entity, was able to detect the initial phishing payloads and isolate the affected workstations within 2 to 20 minutes, cutting off command-and-control (C2) communications before the intrusion could spread. The organization's SOC executed a red team payload on a designated non-privileged host to replicate the access the team would otherwise have obtained, shifting the engagement to an assume-breach model.

    CISA attributed the gap between the two outcomes to the people and processes operating the tools, rather than the tools themselves. The agency noted that "Detection tools are only as effective as the people, processes, and procedures supporting them." This statement underscores the importance of a well-designed and implemented security program in preventing and detecting cyber threats.

    The advisory identified several weaknesses as the main enablers of the compromise, including:

    * Machine Account Quota left at the default, letting any domain user add machine accounts.
    * AD CS certificate templates misconfigured, allowing certificate requests for any user (ESC1).
    * Cleartext credentials for service and database accounts stored on reachable systems.
    * Static cloud access keys set never to expire, with no token revocation in place.
    * Over-permissioned applications in Entra ID able to read mail across all users.

    These vulnerabilities highlight the importance of robust security controls, regular security testing, and employee training in preventing and responding to cyber threats. The incident also serves as a reminder that even the most well-designed security programs can be vulnerable to human error or inadequate processes.

    The advisory is available on the CISA website, and readers are encouraged to review it for further information on the vulnerabilities and mitigation strategies.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISAs-Red-Team-Exercises-A-Cautionary-Tale-of-Vulnerabilities-in-Critical-Infrastructure-ehn.shtml

  • https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html


  • Published: Wed Aug 26 13:15:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us