CISA exposes flaws in two U.S. SOCs
AA26-237A details two red team tests against U.S. critical infrastructure and finds gaps in phishing and Active Directory defenses.
CISA released AA26-237A, an advisory based on two simultaneous red team exercises against critical infrastructure organizations in the United States. In both cases, the red team achieved full domain compromise and access to sensitive business systems and cloud resources, although one organization detected and isolated part of the activity within minutes.
CISA has released advisory AA26-237A, "A Tale of Two SOCs: Insights From Two Red Team Assessments," with results from two simultaneous evaluations against critical infrastructure organizations in the United States. In both exercises, the red team achieved full domain compromise and access to sensitive business systems and cloud resources.
What did the exercise show at the first organization?
The first organization, identified in follow-on coverage as part of the Government Facilities Sector, allowed the red team to move from initial access to lateral movement and privilege escalation without detecting or containing the activity. CISA said the initial foothold came through phishing campaigns sent from an internal email account, which led to the compromise of four workstations.
According to secondary coverage, the red team was even able to read SOC staff emails and deploy keyloggers on their workstations, without any effective response from the organization. CyberPress also linked it to the Government Facilities sector, consistent with other technical coverage placing it in Government Services and Facilities.
How did the second organization respond?
The second organization, which specialized coverage places in the Water and Wastewater Systems Sector, did detect part of the activity and isolated the compromised workstations within an estimated window of 2 to 20 minutes. CISA said the initial access came through spearphishing after the team collected email addresses from public websites and convinced three users to click a malicious link, giving access to three workstations.
After that detection, CISA continued with an assume-breach approach and found weaknesses such as exposed service account credentials and excessive privileges. That allowed access to a domain controller and sensitive authentication details, although operational technology systems were not compromised.
What technical weaknesses did CISA identify?
The advisory points to poor practices and default Active Directory configurations in both environments, including Machine Account Quota and misconfigured Active Directory Certificate Services templates. It also details cleartext credentials, permanent AWS access keys, and Microsoft Entra ID applications with excessive permissions, factors that made it easier to reach sensitive business systems and cloud resources.
CISA also warned about cloud access and security controls, especially the use of applications with Application permissions in Microsoft Entra ID that can access data without user consent. Spanish-language sources noted that neither organization had Conditional Access policies for workload identities or procedures to revoke compromised tokens in cloud environments.
What did CISA ask for based on these findings?
The agency asked organizations to validate monitoring for three specific behaviors, initial access across multiple workstations, domain privilege escalation, and lateral movement, and to measure detection, investigation, quarantine, and escalation times. It also asked for suspicious or criminal activity related to the advisory to be reported to its 24/7 operations center.
Technical and institutional coverage agree that AA26-237A highlights a sharp gap between the two organizations: one never detected the intrusion, while the other isolated systems within minutes. Inside Cybersecurity summarized the advisory as exposing weaknesses in cloud security controls and threat detection at entities in the Government Facilities and Water and Wastewater Systems sectors, along with specific recommendations for critical infrastructure operators.
Sources
- A Tale of Two SOCs: Insights From Two Red Team Assessments (AA26-237A)cisa.gov· Cybersecurity and Infrastructure Security Agency (CISA)
- CISA Red Team Compromises Active Directory and Critical Infrastructurecyberpress.org· CyberPress
- CISA shares results of red team assessment to help orgscybersecurity-help.cz· Cybersecurity Help
- CISA Publishes Critical Infrastructure Red Team Findingsexecutivegov.com· ExecutiveGov
- CISA publica su informe red team: el sector público no detecta ...moncloa.com· Moncloa.com
- CISA details deficiencies in cloud security controls from critical infrastructure red teaminsidecybersecurity.com· Inside Cybersecurity
- CISA Red-Team Exercise Exposes Stark Detection Gap Inside Critical Infrastructure SOCshamerintel.com· HamerIntel
- CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Responsef4n6.co.uk· f4n6
- CISA Red Team Exposes Government SOC Failure and Water Sector Gapsmallory.ai· Mallory AI



