CISA published results of two simultaneous red team assessments that produced sharply different outcomes: both organizations were fully compromised at the domain level, but only one detected the intrusion.
The advisory, tracked as AA26-237A and titled “A Tale of Two SOCs,” was released August 25. Organization A, in the Government Services and Facilities sector, never noticed the red team. Initial access came via a web application with default credentials for built-in accounts, followed by privilege escalation that abused a misconfigured Active Directory Certificate Services template, the same class of certificate-template abuse behind the Certighost domain-takeover exploit. The team then grabbed cleartext credentials, static AWS access keys, and a Primary Refresh Token, and read the security team’s own email to check whether defenders were aware of the activity.
Organization B, a Water and Wastewater Systems entity, detected the initial compromise quickly and quarantined affected systems, blocking the intrusion from spreading further.
CISA said it used similar tradecraft against both targets. The report lands as US water utilities face heightened scrutiny following a wave of attacks on the sector in July, and as the agency pushes critical infrastructure operators to find exposed PLCs before attackers do.
The takeaway for defenders: audit default credentials and certificate templates as attack paths, and test detection and response, not just prevention.
