Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin’s security risk starts when one block gets far more fees than the next

    August 26, 2026

    Scientists may have found a shortcut to calorie restriction’s anti-aging benefits

    August 26, 2026

    As hay fever sufferers grow in Japan, the country is looking to plant no-pollen trees

    August 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin’s security risk starts when one block gets far more fees than the next
    • Scientists may have found a shortcut to calorie restriction’s anti-aging benefits
    • As hay fever sufferers grow in Japan, the country is looking to plant no-pollen trees
    • SLB takes on FEED work to advance North Sea CO2 storage project toward FID
    • Did Iowa’s largest beginning farmer tax credit create more farms?
    • ADHD is no myth – but we should interrogate it all the same | Attention deficit hyperactivity disorder
    • Bexley Council did not send letter advising residents to keep daughters inside – Full Fact
    • Meta reaches $17 billion settlement with US states over social media harm to teens
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 26, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 26, 2026Red Teaming / Security Operations

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.

    Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources.

    The advisory, tracked as AA26-237A and titled “A Tale of Two SOCs,” was released on August 25, 2026. CISA identified the first target only as a Government Services and Facilities Sector organization, referred to as Organization A, and the second as a Water and Wastewater Systems Sector entity, referred to as Organization B.

    “CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses,” the agency said in the advisory.

    Against Organization A, the red team gained initial access after identifying a web application with default credentials for several built-in accounts, which allowed it to send phishing emails from an internal address and land on four workstations.

    It then escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Active Directory Certificate Services (AD CS) template, the same class of certificate-template abuse behind a recently disclosed domain-takeover exploit called Certighost.

    Cybersecurity

    The team went on to access three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static Amazon Web Services (AWS) access keys set never to expire.

    In the cloud, it stole a Primary Refresh Token and abused Entra ID applications carrying elevated permissions to read the security team’s email and check whether defenders were aware of the activity.

    Organization A did not detect any of it. CISA said thousands of false-positive alerts from normal business operations, many rated at higher severity, obscured the alerts the red team generated, and that the organization ran multiple security operations centers (SOCs) and endpoint tools with no shared visibility between them.

    Analysts also lacked escalation procedures and had limited authority to act, and a real alert tied to red team activity on a System Center Configuration Manager (SCCM) server was dismissed as a false positive after defenders could not identify the system’s owner.

    CISA flagged the following weaknesses as the main enablers of the compromise –

    • Machine Account Quota left at the default, letting any domain user add machine accounts.
    • AD CS certificate templates were misconfigured, allowing certificate requests for any user (ESC1).
    • Cleartext credentials for service and database accounts stored on reachable systems.
    • Static cloud access keys set never to expire, with no token revocation in place.
    • Over-permissioned applications in Entra ID able to read mail across all users.

    Organization B, running the same style of attack against it, told a different story. Its SOC detected the initial phishing payloads as each executed and isolated the affected workstations within 2 to 20 minutes, cutting off command-and-control (C2) communications before the intrusion could spread.

    Cybersecurity

    Because that foothold was severed, CISA’s trusted agents at the organization executed a red team payload on a designated non-privileged host to replicate the access the team would otherwise have obtained, shifting the engagement to an assume-breach model.

    From there, the team found the same underlying problems, including cleartext credentials for a domain service account in an SCCM configuration file that carried rights over a domain controller, which it used to run a DCSync attack and retrieve the krbtgt secret.

    The team also reached a bastion host in Organization B’s operational technology (OT) demilitarized zone, but the host blocked outbound internet access, so no C2 channel was established, and the team did not enter the OT systems themselves.

    CISA attributed the gap between the two outcomes to the people and processes operating the tools, rather than the tools themselves.

    “Detection tools are only as effective as the people, processes, and procedures supporting them,” the agency said.

    CISA Compromised critical Detected infrastructure orgs Red Team
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Alibaba’s Qwen Team Releases Qwen3.8-Flash-Next: A 125B Multimodal MoE With 6B Active Parameters Previewing the Qwen4 Architecture

    NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

    The MFA Identity Trap: When Authentication Creates a False Sense of Security

    CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

    Adobe and Nvidia Patch Dozens of Vulnerabilities

    OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin’s security risk starts when one block gets far more fees than the next

    August 26, 2026

    Scientists may have found a shortcut to calorie restriction’s anti-aging benefits

    August 26, 2026

    As hay fever sufferers grow in Japan, the country is looking to plant no-pollen trees

    August 26, 2026

    SLB takes on FEED work to advance North Sea CO2 storage project toward FID

    August 26, 2026
    Latest Posts

    Andy Burnham wants to fix social care. It’s personal for him and for a lot of us too | John Crace

    July 29, 2026

    France orders Russian journalist Xenia Fedorova to leave country over alleged Kremlin propaganda

    July 29, 2026

    Russia-Ukraine War: The Wildberries Theory of Moscow’s Defeat

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin’s security risk starts when one block gets far more fees than the next

    August 26, 2026

    Scientists may have found a shortcut to calorie restriction’s anti-aging benefits

    August 26, 2026

    As hay fever sufferers grow in Japan, the country is looking to plant no-pollen trees

    August 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.