Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

CISA Red Team Gains Full Domain Control of Two Critical Infrastructure Organizations, Exposing Detection Gaps

CISA’s red‑team exercises showed full domain takeover of a government services entity and a water‑utility operator, with one org never detecting the breach. The incident underscores the need for SOC 2‑aligned alert tuning, credential hygiene, and continuous evidence collection for audit readiness.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

CISA Red Team Gains Full Domain Control of Two Critical Infrastructure Organizations, Exposing Detection Gaps

What Happened – CISA’s own red‑team exercises revealed that two critical‑infrastructure entities—one in the Government Services sector and another in the Water & Wastewater sector—lost complete domain control and had their cloud environments compromised. Organization A never detected the intrusion, while Organization B isolated the hosts within minutes.

Why It Matters for Compliance & Audit Readiness

  • Full‑domain compromise and undetected activity illustrate a failure of the SOC 2 Security principle to “detect, prevent, and respond to system‑intrusion attempts.”
  • The reliance on default credentials and a mis‑configured AD Certificate Services template highlights gaps in Access Control (CC6.1) and Change Management (CC7.1) that must be documented and continuously monitored.
  • Continuous evidence of alert‑tuning, incident‑response playbooks, and credential‑hygiene controls is essential to provide a defensible audit trail—exactly what Verisq’s Control Mapping capability helps organizations capture.

Who Is Affected – Government Services & Facilities sector; Water and Wastewater Systems sector.

Recommended Actions –

  • Map the compromised AD Certificate Services template to SOC 2 CC6.1 (Access Control) and CC7.1 (Change Management).
  • Implement credential‑hygiene policies (no default passwords) and enforce MFA for privileged accounts.
  • Tune SIEM/alerting rules to reduce false positives and ensure high‑severity alerts are triaged promptly.
  • Capture continuous evidence of alert‑tuning, incident‑response drills, and remediation steps for audit readiness.

Source: Security Affairs – CISA Red Team Fully Compromised Two Critical Infrastructure Orgs

Technical Notes – Attack vector combined default‑credential exploitation, phishing from a trusted internal address, and a mis‑configured Active Directory Certificate Services (ESC1) template that allowed low‑privilege users to request high‑privilege certificates. No specific CVE was cited, but the flaw is a known misconfiguration in AD CS. Cloud resources were later accessed, and SOC staff emails were read to confirm the breach went unnoticed.

📰 Original Source
https://securityaffairs.com/197901/hacking/cisa-red-team-fully-compromised-two-critical-infrastructure-orgs.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →