Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Red Team Exposes Security Gaps in Key Infrastructure

CISA Red Team Exposes Security Gaps in Key Infrastructure

Posted on August 26, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently shared findings from its red team assessments of two critical infrastructure entities, showcasing varied defensive reactions despite employing similar strategies. Both entities were breached at the domain level, with access gained to sensitive business systems and cloud resources.

Red Team Assessment Overview

Dated August 25, 2026, CISA’s advisory, labeled AA26-237A and titled “A Tale of Two SOCs,” details the assessments on two organizations: a Government Services and Facilities Sector entity, referred to as Organization A, and a Water and Wastewater Systems Sector entity, known as Organization B. The evaluations highlighted significant differences in how each organization handled security threats.

For Organization A, the red team exploited a web application using default credentials, enabling them to dispatch phishing emails internally and compromise multiple workstations. The team further elevated their access by manipulating an Active Directory Certificate Services (AD CS) template and using stored cleartext credentials to infiltrate three sensitive business systems.

Organization A’s Security Challenges

Organization A’s defenses failed to detect these breaches, largely due to an overwhelming number of false-positive alerts that masked genuine threats. Multiple security operations centers (SOCs) and endpoint tools operated without shared visibility, and analysts lacked the necessary escalation processes and authority, leading to the dismissal of critical alerts as false positives.

CISA identified several vulnerabilities within Organization A: default Machine Account Quota settings, misconfigured AD CS templates, insecure storage of cleartext credentials, static cloud keys without expiration, and excessive permissions in Entra ID applications.

Organization B’s Proactive Defense

In contrast, Organization B’s SOC quickly identified and neutralized phishing payloads within minutes, isolating affected systems and preventing command-and-control communications. To simulate further access, CISA’s agents executed a red team payload on a non-privileged host, revealing similar underlying issues but without any further breach into its operational technology systems due to effective network restrictions.

CISA credited Organization B’s success to its adept personnel and robust processes, emphasizing that detection tools are only as effective as the teams managing them.

Ultimately, these assessments underscore the critical role of skilled personnel and processes in enhancing cybersecurity defenses, beyond just the technological tools employed.

The Hacker News Tags:CISA, cloud security, critical infrastructure, Cybersecurity, Organization A, Organization B, phishing attack, red teaming, security operations, SOC

Post navigation

Previous Post: OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
Next Post: AI Accelerates Malware Creation, But Not Its Effectiveness

Related Posts

Microsoft Highlights AI Vulnerability to Tool Description Attacks Microsoft Highlights AI Vulnerability to Tool Description Attacks The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
Critical Telnetd Security Flaw Allows Remote Code Execution Critical Telnetd Security Flaw Allows Remote Code Execution The Hacker News
New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP The Hacker News
AI’s Impact on Cybersecurity Response Times AI’s Impact on Cybersecurity Response Times The Hacker News
Lazarus Group Targets Finance with RemotePE Malware Lazarus Group Targets Finance with RemotePE Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark