Critical Infrastructure Security

CISA red team finds critical infrastructure vulnerabilities

(Adobe Stock)

As outlined in Security Affairs, CISA conducted simultaneous red team assessments at two critical infrastructure organizations, revealing significant disparities in their cybersecurity defenses and incident response capabilities. Both organizations experienced full domain compromise and had their cloud environments breached, but only one detected the intrusion.

The assessments, detailed in CISA advisory AA26-237A, targeted a Government Services and Facilities Sector entity (Organization A) and a Water and Wastewater Systems Sector entity (Organization B). Both red teams employed similar attack vectors, including exploiting default credentials and Active Directory Certificate Services flaws. Organization A, overwhelmed by false positives and lacking clear escalation procedures, failed to detect the breach until CISA informed them. In contrast, Organization B's security operations center rapidly identified and contained the initial compromise attempts.

Despite these differences, both organizations shared a cloud security gap: the absence of Conditional Access for workload identities, which allowed the red team to access sensitive emails. Organization B also had a password exposed in plain text and a path into its OT network.

CISA recommends hardening Active Directory Certificate Services, managing endpoint management platforms as Tier 0 assets, and enabling Conditional Access for workload identities to improve defenses.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds