Executive Summary
In August 2026, CISA published results from simultaneous red team assessments against two critical infrastructure organizations in the Government Services and Water/Wastewater sectors. Both organizations were fully compromised at the domain level using similar attack techniques including web application exploitation with default credentials, Active Directory Certificate Services misconfigurations, and privilege escalation through cleartext stored credentials. Organization A detected nothing despite thousands of security alerts, while Organization B's SOC detected and isolated affected workstations within 2-20 minutes, demonstrating the critical importance of security operations maturity over tool sophistication.
This assessment highlights the growing focus on defensive capabilities amid increasing nation-state threats against critical infrastructure, particularly following recent campaigns like Salt Typhoon that exposed fundamental gaps in network security and detection capabilities across sectors.
Why This Matters Now
Critical infrastructure remains highly vulnerable to basic attack techniques, with detection capabilities varying dramatically between organizations despite similar security tooling, emphasizing urgent need for SOC maturity improvements.
Attack Path Analysis
CISA's red team achieved full domain compromise in both organizations by exploiting web applications with default credentials, escalating privileges through AD CS misconfigurations and machine account quota abuse, moving laterally using cleartext stored credentials, establishing C2 channels (blocked in Organization B), accessing cloud resources via static AWS keys and Entra ID over-permissions, and demonstrating potential business system impact including OT environment access.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Red team identified web applications with default credentials for built-in accounts, used these to send phishing emails from internal addresses and gained access to four workstations
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Valid Accounts: Cloud Accounts
Exploitation for Privilege Escalation
Unsecured Credentials: Credentials In Files
OS Credential Dumping: DCSync
Email Collection: Remote Email Collection
Remote Services: Remote Desktop Protocol
Use Alternate Authentication Material: Application Access Token
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Privileged Account Management
Control ID: Identity-2
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
ISO 27001:2022 – Privileged Access Rights
Control ID: A.8.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Government Services organization fully compromised with zero detection capability, exposing critical infrastructure vulnerabilities to domain-level breaches and cloud resource theft.
Utilities
Water and Wastewater Systems sector targeted with OT network infiltration attempts, demonstrating industrial control system exposure despite improved detection capabilities.
Information Technology/IT
Critical infrastructure IT systems compromised through Active Directory misconfigurations, cleartext credentials, and cloud token abuse requiring enhanced zero trust segmentation.
Computer/Network Security
Security operations centers demonstrated vast capability gaps in threat detection, alert management, and incident response procedures during simultaneous red team exercises.
Sources
- CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothinghttps://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.htmlVerified
- CISA Advisory AA26-237A: A Tale of Two SOCs - Red Team Assessment Resultshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237aVerified
- CISA Red Team Assessments and Critical Infrastructure Securityhttps://www.cisa.gov/topics/cybersecurity-best-practices/red-team-assessmentsVerified
- Active Directory Certificate Services Template Exploitation Researchhttps://posts.specterops.io/certified-pre-owned-d95910965cd2Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-stage attack by limiting lateral movement between network segments and reducing the blast radius of the domain compromise across cloud and on-premises environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Workstation compromise scope would likely have been reduced through microsegmentation policies that limit initial foothold expansion and contain compromised endpoints within isolated network segments.
Control: Zero Trust Segmentation
Mitigation: Domain controller access and DCSync attack reach would likely have been constrained through segmentation policies that limit privileged account movements and restrict certificate authority communications to authorized endpoints only.
Control: East-West Traffic Security
Mitigation: Access to sensitive business systems and OT bastion hosts would likely have been significantly restricted through east-west traffic inspection and policy enforcement between network segments and operational technology environments.
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment would likely have been detected faster and contained more effectively through enhanced visibility into cross-cloud communications and automated response capabilities across hybrid infrastructure environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration scope would likely have been reduced through controlled egress policies that limit cloud resource access patterns and restrict the volume and destinations of sensitive data transfers.
While domain compromise occurred, the overall business impact would likely have been contained to isolated network segments, reducing the potential for widespread operational technology disruption and limiting exposure of critical business systems.
Impact at a Glance
Affected Business Functions
- Security Operations Center (SOC) Management
- Critical Infrastructure Monitoring
- Incident Response and Detection
- Network Security Operations
Estimated downtime: N/A
Estimated loss: N/A
This was a controlled red team assessment where CISA gained access to sensitive business systems, cloud resources, and security team emails. Organization A had complete compromise with no detection, while Organization B successfully detected and contained the initial attack vectors. The exercise exposed significant security gaps including cleartext credentials, misconfigured certificate services, and inadequate SOC procedures.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with least privilege policies to prevent lateral movement between workstations and sensitive business systems
- • Deploy egress security controls with FQDN filtering to block unauthorized C2 communications and data exfiltration attempts
- • Enable east-west traffic inspection and anomaly detection to identify suspicious inter-system communications and credential abuse
- • Establish multicloud visibility and centralized policy enforcement to monitor AWS access key usage and Entra ID application permissions
- • Deploy threat detection capabilities with proper SOC procedures, shared visibility between security tools, and clear escalation authority to ensure rapid incident response



