Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Red Team Exposes Security Gaps in Key Infrastructure

CISA Red Team Exposes Security Gaps in Key Infrastructure

Posted on August 26, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently shared findings from its red team assessments of two critical infrastructure entities, showcasing varied defensive reactions despite employing similar strategies. Both entities were breached at the domain level, with access gained to sensitive business systems and cloud resources.

Red Team Assessment Overview

Dated August 25, 2026, CISA’s advisory, labeled AA26-237A and titled “A Tale of Two SOCs,” details the assessments on two organizations: a Government Services and Facilities Sector entity, referred to as Organization A, and a Water and Wastewater Systems Sector entity, known as Organization B. The evaluations highlighted significant differences in how each organization handled security threats.

For Organization A, the red team exploited a web application using default credentials, enabling them to dispatch phishing emails internally and compromise multiple workstations. The team further elevated their access by manipulating an Active Directory Certificate Services (AD CS) template and using stored cleartext credentials to infiltrate three sensitive business systems.

Organization A’s Security Challenges

Organization A’s defenses failed to detect these breaches, largely due to an overwhelming number of false-positive alerts that masked genuine threats. Multiple security operations centers (SOCs) and endpoint tools operated without shared visibility, and analysts lacked the necessary escalation processes and authority, leading to the dismissal of critical alerts as false positives.

CISA identified several vulnerabilities within Organization A: default Machine Account Quota settings, misconfigured AD CS templates, insecure storage of cleartext credentials, static cloud keys without expiration, and excessive permissions in Entra ID applications.

Organization B’s Proactive Defense

In contrast, Organization B’s SOC quickly identified and neutralized phishing payloads within minutes, isolating affected systems and preventing command-and-control communications. To simulate further access, CISA’s agents executed a red team payload on a non-privileged host, revealing similar underlying issues but without any further breach into its operational technology systems due to effective network restrictions.

CISA credited Organization B’s success to its adept personnel and robust processes, emphasizing that detection tools are only as effective as the teams managing them.

Ultimately, these assessments underscore the critical role of skilled personnel and processes in enhancing cybersecurity defenses, beyond just the technological tools employed.

The Hacker News Tags:CISA, cloud security, critical infrastructure, Cybersecurity, Organization A, Organization B, phishing attack, red teaming, security operations, SOC

Post navigation

Previous Post: OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
Next Post: AI Accelerates Malware Creation, But Not Its Effectiveness

Related Posts

Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials The Hacker News
Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware The Hacker News
Critical Linux Flaw ‘Copy Fail’ Allows Root Access Critical Linux Flaw ‘Copy Fail’ Allows Root Access The Hacker News
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs The Hacker News
AI Security Lags Behind as Skills Fail to Evolve AI Security Lags Behind as Skills Fail to Evolve The Hacker News
Adobe Tackles Major Security Flaws in ColdFusion and Campaign Adobe Tackles Major Security Flaws in ColdFusion and Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bug in WordPress Plugin Risks 400,000 Sites
  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bug in WordPress Plugin Risks 400,000 Sites
  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark