CISA Demonstrates the Defensive Gap in Two Critical Infrastructures
CISA has published the results of two red team assessments conducted in parallel against two critical infrastructure organizations. In both environments, the testers were able to achieve full domain compromise and access sensitive business systems and cloud assets. The key difference was the response capability: one organization did not detect or contain the activity, while the other quickly identified the initial compromise, isolated the affected systems, and forced the red team into an assume-breach model. The two victims belong to the Government Services and Facilities and Water and Wastewater sectors, respectively. The report matters because it shows that the issue is not only preventing initial access, but also recognizing and stopping an attacker already inside the network quickly. CISA formalized the findings in advisory AA26-237A, highlighting how important visibility, segmentation, and operational response are.
Source: Security Affairs


Leave a Reply