Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes

TL;DR Summary
Two parallel CISA red-team assessments against two critical infrastructure orgs produced opposite results: Org A was fully compromised at the domain level with access to sensitive business systems and cloud resources, while Org B detected the phishing quickly and cut off command-and-control, then reproduced access via an assume-breach test. The common weaknesses—cleartext credentials, misconfigured AD CS, default machine account quota, static cloud keys, and over-permissioned Entra ID—are attributed more to people and processes than to tools.
- CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing The Hacker News
- Water sector passes, government sector fails attempts to spot and halt simulated CISA attack CyberScoop
- Red Team Discoveries Support Organizations in Assessing Risk Security Magazine
- CISA Red Team Test Finds Key Weaknesses RTO Insider
- CISA Rolls Out Red Team Advisory to Sharpen Cyber Defense Practices Across Critical Infrastructure ExecutiveGov
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
3 min
vs 4 min read
Condensed
88%
659 → 76 words
Want the full story? Read the original article
Read on The Hacker News