Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA AA26-237A red team assessment results

Public Sector Action
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

CISA released AA26-237A, publishing the results of two simultaneous red team assessments against two critical infrastructure organizations and exposing major gaps in detection, response, and visibility. Organization A was fully compromised at the domain level and missed the activity entirely, while Organization B isolated phishing-infected workstations within 2 to 20 minutes. The advisory shows how SOC coordination and operational discipline can determine whether the same intrusion path is contained early or allowed to spread into cloud resources and sensitive business systems.

Related Happenings

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure

Public Sector Action
H score28 First: 28.07.2026 21:41 Last: 28.07.2026 21:41 Sources 1

About this happening: CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...

CISA warning on FortiBleed for FortiGate customers

Public Sector Action
H score89 First: 19.06.2026 17:00 Last: 19.06.2026 17:00 Sources 1

About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...

CISA KEV directive for CVE-2026-20133

Public Sector Action
H score36 First: 21.04.2026 15:30 Last: 21.04.2026 15:30 Sources 1

About this happening: On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...

CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory

Advisory/Mitigation
H score32 First: 08.04.2026 11:15 Last: 08.04.2026 11:15 Sources 1

About this happening: CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...

Timeline

  1. 26.08.2026 16:07 1 articles · 4h ago

    Organization A is fully compromised through default credentials and AD CS abuse

    Victim Impact Update

    Organization A, a Government Services and Facilities Sector target, is fully compromised at the domain level after a web application with default credentials for built-in accounts lets the red team send phishing emails from an internal address and land on four workstations. Privilege escalation follows through a default Machine Account Quota and a misconfigured Active Directory Certificate Services template, then cleartext credentials, decrypted database configuration files, and static Amazon Web Services (AWS) access keys open three sensitive business systems and cloud resources. In the cloud, a Primary Refresh Token is stolen and Entra ID applications with elevated permissions are abused to read the security team's email and check whether defenders are aware of the activity, while the organization does not detect the activity and a real SCCM alert is dismissed as a false positive amid thousands of noisy alerts and no shared SOC visibility.

    Show sources
  2. 26.08.2026 16:07 1 articles · 4h ago

    Organization B detects phishing payloads and isolates workstations within minutes

    Detection Ioc Update

    Organization B, a Water and Wastewater Systems Sector target, detects the initial phishing payloads as each one executes and isolates the affected workstations within 2 to 20 minutes, cutting off command-and-control before the intrusion can spread. After the foothold is severed, trusted agents at the organization execute a red team payload on a designated non-privileged host to support an assume-breach model, and the team still reaches the same underlying weaknesses, including an SCCM configuration file with cleartext credentials for a domain service account that has rights over a domain controller and is used for DCSync to retrieve the krbtgt secret. The engagement also reaches a bastion host in the operational technology demilitarized zone, but outbound internet access is blocked and no C2 channel is established, so the OT systems themselves are not entered.

    Show sources
  3. 26.08.2026 16:07 2 articles · 4h ago

    CISA releases AA26-237A on simultaneous red team assessments

    Initial Disclosure

    CISA releases AA26-237A, "A Tale of Two SOCs," describing simultaneous red team assessments against a Government Services and Facilities Sector organization and a Water and Wastewater Systems Sector entity, with both targets fully compromised at the domain level. The advisory contrasts a complete lack of detection at Organization A with rapid detection and containment at Organization B and frames the outcome gap as a people-and-process problem rather than a tooling problem.

    Show sources