CISA Red Team Compromises Two Critical Infrastructure Orgs; One SOC Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
CISA's red team abused a misconfigured AD CS certificate template (ESC1) to escalate privileges, a technique similar to the Certighost exploit, emphasizing…