"Detection tools are only as effective as the people, processes, and procedures supporting them," the agency said.
AA26-237A and two simultaneous red-team engagements (Aug. 25, 2026)
On August 25, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs." The advisory summarized two red team assessments run at the same time against two critical infrastructure organizations — a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector entity (Organization B) — using similar tradecraft but producing sharply different outcomes.
Organization A: domain takeover, cloud token theft, and no detection
The red team fully compromised Organization A at the domain level. Initial access began after the team found a web application with default credentials for several built-in accounts. Those credentials allowed the team to send phishing emails from an internal address and successfully land on four workstations.
Privilege escalation followed the abuse of a default Machine Account Quota and a misconfigured Active Directory Certificate Services (AD CS) template — the same class of certificate-template abuse associated with the recently disclosed Certighost domain-takeover exploit. The team accessed three sensitive business systems using credentials stored in cleartext, including decrypted database configuration files and static Amazon Web Services (AWS) access keys set never to expire.
In Organization A's cloud environment, the red team stole a Primary Refresh Token and abused Entra ID applications that carried elevated permissions to read the security team's email and check whether defenders were aware of the activity. CISA reported that Organization A detected none of these actions.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOrganization B: fast isolation, assume-breach pivot, and blocked OT exfiltration
By contrast, Organization B's SOC detected the red team's phishing payloads as they executed and isolated the affected workstations within 2 to 20 minutes, severing command-and-control communications before the intrusion could spread. Because that foothold was cut off, CISA's trusted agents at Organization B executed a red team payload on a designated non-privileged host to replicate the access the team would otherwise have obtained — an explicit shift to an assume-breach model.
The team still found serious technical failings at Organization B: cleartext credentials for a domain service account in an SCCM configuration file carried rights over a domain controller and were used to run a DCSync attack to retrieve the krbtgt secret. The red team reached a bastion host in the organization's operational technology (OT) demilitarized zone, but that host blocked outbound internet access, preventing the establishment of a C2 channel and limiting any movement into OT systems.
Technical misconfigurations that enabled both compromises
- Machine Account Quota left at the default, permitting any domain user to add machine accounts.
- AD CS certificate templates misconfigured, allowing certificate requests for any user (ESC1).
- Cleartext credentials for service and database accounts stored on reachable systems.
- Static cloud access keys set never to expire, and no token revocation in place.
- Over-permissioned applications in Entra ID able to read mail across all users.
Why the outcomes diverged: people, processes, and SOC integration
CISA attributed the different results to the people and processes operating defensive tools rather than to the tools themselves. In Organization A, thousands of false-positive alerts from normal business operations — many rated at higher severity — obscured the red team’s alerts. The organization ran multiple SOCs and endpoint tools that lacked shared visibility, analysts had limited escalation procedures and authority, and a genuine alert tied to red team activity on an SCCM server was dismissed as a false positive when defenders could not identify the system's owner.
Organization B’s SOC, by contrast, detected, isolated, and contained initial execution within minutes, and network controls on an OT bastion stopped outbound traffic that would have enabled exfiltration or C2. Those operational differences, CISA said, were decisive.
What this means for technologists, regulators, and water utilities
Technologists and security teams: The advisory ties identical technical failings — default quotas, misconfigured AD CS templates, cleartext credentials, non-expiring cloud keys, and over-permissioned Entra ID apps — to domain compromise and cloud token theft. Detection alone did not prevent loss: integrated visibility, clear escalation procedures, and the authority to act were the differentiators.
Regulators and procurement leaders: CISA’s findings highlight how tool deployments without shared visibility and operational alignment can produce unreadable alert noise. Procurement and oversight decisions that assume tool parity equals defense parity will not address the gaps CISA flagged.
Water and wastewater system operators: Organization B’s rapid workstation isolation and network controls in the OT DMZ prevented lateral movement and C2; however, the presence of high‑privilege cleartext credentials and the ability to perform DCSync show that detection and containment worked despite persistent configuration weaknesses.
The advisory paints a stark, specific contrast: identical tradecraft and the same underlying vulnerabilities produced opposite results because of how defenders organized and acted. Fixing machine-account quotas, AD CS templates, credential handling, cloud token policies, and application permissions is necessary, CISA shows, but not sufficient without integrated SOC visibility, escalation procedures, and the authority to move from detection to containment. The agency’s record leaves one practical question: which organizations will pair those technical fixes with the human and procedural changes CISA identified as decisive?
https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html




