The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled “A Tale of Two SOCs,” on August 25, 2026, detailing the results of two simultaneous red team assessments against critical infrastructure organizations. Both organizations were fully compromised at the domain level, with the red team reaching sensitive business systems and cloud resources. However, the defensive outcomes were starkly different.
Organization A, a Government Services and Facilities Sector entity, was compromised without detection. The red team gained initial access by exploiting default credentials on a web application, then escalated privileges by abusing a default Machine Account Quota and a misconfigured Active Directory Certificate Services (AD CS) template (ESC1). They accessed sensitive business systems using cleartext credentials and static AWS access keys, stole a Primary Refresh Token, and abused over-permissioned Entra ID applications to read the security team’s email. CISA attributed the lack of detection to thousands of false-positive alerts, multiple SOCs with no shared visibility, and analysts lacking escalation procedures.
Organization B, a Water and Wastewater Systems Sector entity, detected the initial phishing payloads within 2 to 20 minutes, isolated affected workstations, and severed command-and-control communications. The engagement shifted to an assume-breach model. The red team still found cleartext credentials in an SCCM configuration file, enabling a DCSync attack to retrieve the krbtgt secret, and reached a bastion host in the OT DMZ, but outbound internet access was blocked, preventing C2. CISA emphasized that detection tools are only as effective as the people and processes supporting them.
CVEs: CVE-2026-58231
Companies: CISA, Amazon Web Services, Microsoft
Products: Active Directory Certificate Services, Entra ID, System Center Configuration Manager
Original source: thehackernews.com