Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes

1 min read
Source: The Hacker News
Two Red-Team Breaches, Two Outcomes: CISA Links Detection Gaps to People and Processes
Photo: The Hacker News
TL;DR Summary

Two parallel CISA red-team assessments against two critical infrastructure orgs produced opposite results: Org A was fully compromised at the domain level with access to sensitive business systems and cloud resources, while Org B detected the phishing quickly and cut off command-and-control, then reproduced access via an assume-breach test. The common weaknesses—cleartext credentials, misconfigured AD CS, default machine account quota, static cloud keys, and over-permissioned Entra ID—are attributed more to people and processes than to tools.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

88%

65976 words

Want the full story? Read the original article

Read on The Hacker News