CISA’s parallel red-team assessments of an unnamed government organization and a water-sector organization found that both were initially compromised through phishing and Active Directory weaknesses, including default Machine Account Quota settings and misconfigured Active Directory Certificate Services templates. The simulated attackers escalated privileges and moved laterally; at the government organization, they reached sensitive business systems and cloud resources without effective detection, read SOC personnel email, and deployed keyloggers on defender workstations.
The water-sector organization detected and isolated compromised endpoints within 2 to 20 minutes, disrupted command-and-control traffic, and continued identifying malicious activity after CISA adopted an assume-breach posture. CISA attributed the divergent outcomes primarily to SOC operational maturity—alert triage, escalation authority, and cross-team communication—rather than security tooling. Both assessments identified cloud and identity-control gaps, including absent Conditional Access for workload identities and weak procedures for revoking compromised access and refreshing tokens; CISA urged operators to remediate AD weaknesses and strengthen identity controls and incident-response processes.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
CISA first published an advisory on its red-team activity.
CISA publicly released an advisory and report describing the two voluntary red-team engagements, contrasting the government organization's ineffective response with the water-sector organization's rapid containment. The agency urged organizations to remediate Active Directory and certificate-template weaknesses, strengthen credential and cloud-identity controls, and improve SOC escalation, coordination, and analyst authority.
With trusted access simulating an undetected compromise, CISA exploited the Machine Account Quota weakness, harvested SCCM credentials, conducted DCSync activity, and moved toward business, cloud, and OT DMZ systems. Defenders isolated a compromised OT-DMZ bastion host and blocked a suspicious Azure sign-in, demonstrating continued layered detection.
In a parallel assessment of a Water and Wastewater Systems Sector organization, three users clicked spearphishing links, but the SOC quarantined affected workstations within 2, 10, and 20 minutes and cut off command-and-control communications. CISA then shifted the exercise to an assume-breach model after the initial intrusion was detected.
During a red-team assessment of a Government Services and Facilities Sector organization, CISA gained access through phishing, escalated domain privileges through Active Directory weaknesses, and reached sensitive business systems and cloud resources without detection. The team also read SOC personnel emails and deployed keyloggers on defenders' machines; CISA attributed the ineffective response to alert overload, organizational silos, and inadequate escalation processes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcethehackernews.com
Open sourcecyberscoop.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.