As outlined in Security Affairs, CISA conducted simultaneous red team assessments at two critical infrastructure organizations, revealing significant disparities in their cybersecurity defenses and incident response capabilities. Both organizations experienced full domain compromise and had their cloud environments breached, but only one detected the intrusion.The assessments, detailed in CISA advisory AA26-237A, targeted a Government Services and Facilities Sector entity (Organization A) and a Water and Wastewater Systems Sector entity (Organization B). Both red teams employed similar attack vectors, including exploiting default credentials and Active Directory Certificate Services flaws. Organization A, overwhelmed by false positives and lacking clear escalation procedures, failed to detect the breach until CISA informed them. In contrast, Organization B's security operations center rapidly identified and contained the initial compromise attempts.Despite these differences, both organizations shared a cloud security gap: the absence of Conditional Access for workload identities, which allowed the red team to access sensitive emails. Organization B also had a password exposed in plain text and a path into its OT network.CISA recommends hardening Active Directory Certificate Services, managing endpoint management platforms as Tier 0 assets, and enabling Conditional Access for workload identities to improve defenses.Source: Security Affairs
Critical Infrastructure Security
CISA red team finds critical infrastructure vulnerabilities
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
