CybersecurityAugust 27, 2026· via Security Affairs

CISA red teams expose gaping holes in critical infrastructure defenses

CISA red teams expose gaping holes in critical infrastructure defenses

Image : Security Affairs

A U.S. Cybersecurity and Infrastructure Security Agency (CISA) red team drilled two critical infrastructure organizations simultaneously—one never noticed, the other contained the breach within minutes. In both cases, attackers gained full domain control, accessed sensitive systems, and even rummaged through the first victim’s SOC emails—all undetected until CISA’s post-mortem.

Two very different outcomes from the same playbook

CISA’s advisory AA26-237A describes how “Organization A,” a Government Services and Facilities Sector entity, was compromised for weeks without a single alert. Attackers exploited a web app still running default credentials, sent phishing emails from an internal address, and pivoted to four workstations. They then weaponized a misconfigured Active Directory Certificate Services template (ESC1) to mint admin certificates and move laterally—including into cloud environments—while SOC analysts chased thousands of false positives.

Meanwhile, “Organization B,” in the Water and Wastewater Systems Sector, spotted the intrusion early, isolated systems, and forced the red team into an assume-breach posture. The difference wasn’t the attackers’ skill, CISA stresses, but detection and response discipline.

Alert fatigue and siloed SOCs sealed the first victim’s fate

CISA’s report highlights how Organization A’s SOC was drowning in noise: high-severity false positives buried the real intrusion signals. Analysts reviewing SCCM alerts couldn’t identify the system’s owner, dismissed the activity as routine, and marked it a false positive—while the attackers watched. Multiple SOCs with mismatched EDR tools and no shared visibility compounded the problem. Even when one team noticed something, there was no clear escalation path or written procedure; staff defaulted to waiting, giving attackers free rein.

Why it matters

The episode underscores that detection tools alone won’t stop intrusions—people, processes, and coordination do. Organizations with fragmented SOCs, bloated alert queues, and weak escalation protocols risk missing real threats in plain sight. CISA’s findings serve as a wake-up call: invest in alert tuning, cross-team visibility, and unambiguous incident response playbooks, or risk becoming the next Organization A—unaware until it’s too late.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home