Cyber Security News

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is because trained analysts are needed to respond to alerts effectively.

The agency’s “A Tale of Two SOCs” report compares two parallel red team engagements: one against a Government Services and Facilities Sector organization and another against a Water and Wastewater Systems Sector entity, using nearly identical attack tradecraft but producing starkly different outcomes.

In both cases, CISA’s operators used phishing to gain an initial foothold, then leaned on Active Directory misconfigurations such as a default Machine Account Quota and misconfigured Active Directory Certificate Services templates to escalate privileges and move laterally.

CISA Red Team Breaches Critical Infrastructure

At Organization A, the team gained elevated domain privileges and reached sensitive business systems and cloud resources entirely undetected, eventually reading SOC staff emails and deploying keyloggers on defenders’ own machines without triggering a response.

Organization B told a different story: its SOC isolated compromised workstations within 2 to 20 minutes of the initial phishing payload executing, cutting off command-and-control communications before the intrusion could spread.

Because Organization B caught the breach so quickly, CISA shifted to an “assume breach” model, with trusted agents granting the red team access equivalent to what they would have had if the phishing attempt had gone unnoticed.

From there, the team again escalated privileges through the same Machine Account Quota weakness, harvested cleartext credentials via a System Center Configuration Manager file, and used DCSync attacks to obtain domain controller credentials, including the sensitive krbtgt account used to forge Golden Tickets.

Despite this deep access, Organization B’s defenders isolated a compromised bastion host in the operational technology demilitarized zone and blocked a suspicious Azure sign-in flagged by Microsoft’s automated alerting, showing that layered detection kept working even after the network was assumed compromised.

CISA attributes Organization A’s blind spots not to a lack of tools but to operational dysfunction. The organization ran multiple SOCs and multiple EDR platforms without cross-team communication, and thousands of false-positive alerts from routine business activity buried the genuine indicators of compromise.

Analysts also lacked standard operating procedures for escalating suspicious activity and had limited authority to act, so real alerts, including one tied to red team activity on an SCCM server, were dismissed as false positives after defenders simply couldn’t identify the system owner.

The advisory’s central takeaway is that detection tooling is only as effective as the humans and processes behind it. CISA is urging critical infrastructure operators to fix common Active Directory weaknesses such as unrestricted Machine Account Quotas and ESC1-vulnerable certificate templates, enforce credential expiration for service and cloud accounts, and adopt Conditional Access for workload identities to close gaps around application permissions.

Just as importantly, organizations need documented escalation procedures, cross-team visibility, and empowered analysts, since Organization B’s success came down to fast triage and decisive isolation rather than any single security product.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

1 hour ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

2 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

2 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

2 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

3 hours ago

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

3 hours ago