← Back to feed
Breaches & RansomwareEmerging1 sourceAug 25, 2026 · 16:45via Cyber Security News

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

Brief

CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is because trained analysts are needed to respond to alerts effectively.

The agency’s “A Tale of Two SOCs” report compares two parallel red team engagements: one against a Government Services and Facilities Sector organization and another against a Water and Wastewater Systems Sector entity, using nearly identical attack tradecraft but producing starkly different outcomes.

In both cases, CISA’s operators used phishing to gain an initial foothold, then leaned on Active Directory misconfigurations such as a default Machine Account Quota and misconfigured Active Directory Certificate Services templates to escalate privileges and move laterally.

Read more on Cyber Security News