Cyber Security News

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is because trained analysts are needed to respond to alerts effectively.

The agency’s “A Tale of Two SOCs” report compares two parallel red team engagements: one against a Government Services and Facilities Sector organization and another against a Water and Wastewater Systems Sector entity, using nearly identical attack tradecraft but producing starkly different outcomes.

In both cases, CISA’s operators used phishing to gain an initial foothold, then leaned on Active Directory misconfigurations such as a default Machine Account Quota and misconfigured Active Directory Certificate Services templates to escalate privileges and move laterally.

CISA Red Team Breaches Critical Infrastructure

At Organization A, the team gained elevated domain privileges and reached sensitive business systems and cloud resources entirely undetected, eventually reading SOC staff emails and deploying keyloggers on defenders’ own machines without triggering a response.

Organization B told a different story: its SOC isolated compromised workstations within 2 to 20 minutes of the initial phishing payload executing, cutting off command-and-control communications before the intrusion could spread.

Because Organization B caught the breach so quickly, CISA shifted to an “assume breach” model, with trusted agents granting the red team access equivalent to what they would have had if the phishing attempt had gone unnoticed.

From there, the team again escalated privileges through the same Machine Account Quota weakness, harvested cleartext credentials via a System Center Configuration Manager file, and used DCSync attacks to obtain domain controller credentials, including the sensitive krbtgt account used to forge Golden Tickets.

Despite this deep access, Organization B’s defenders isolated a compromised bastion host in the operational technology demilitarized zone and blocked a suspicious Azure sign-in flagged by Microsoft’s automated alerting, showing that layered detection kept working even after the network was assumed compromised.

CISA attributes Organization A’s blind spots not to a lack of tools but to operational dysfunction. The organization ran multiple SOCs and multiple EDR platforms without cross-team communication, and thousands of false-positive alerts from routine business activity buried the genuine indicators of compromise.

Analysts also lacked standard operating procedures for escalating suspicious activity and had limited authority to act, so real alerts, including one tied to red team activity on an SCCM server, were dismissed as false positives after defenders simply couldn’t identify the system owner.

The advisory’s central takeaway is that detection tooling is only as effective as the humans and processes behind it. CISA is urging critical infrastructure operators to fix common Active Directory weaknesses such as unrestricted Machine Account Quotas and ESC1-vulnerable certificate templates, enforce credential expiration for service and cloud accounts, and adopt Conditional Access for workload identities to close gaps around application permissions.

Just as importantly, organizations need documented escalation procedures, cross-team visibility, and empowered analysts, since Organization B’s success came down to fast triage and decisive isolation rather than any single security product.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

3 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

9 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

20 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago