← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 26, 2026 · 23:20via Security Affairs

CISA Red Team Fully Compromised Two Critical Infrastructure Orgs

Brief

CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach.

CISA published an advisory ( AA26-237A ) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA told them afterward.

“The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources.” states CISA .

Read more on Security Affairs