Overview
- CISA published advisory AA26-237A on August 25, 2026, after running two simultaneous red-team assessments that achieved full domain control and cloud access in both tested organizations.
- One target, a government-sector organization, missed the intrusion because thousands of noisy alerts and siloed SOCs hid real signals and analysts lacked clear escalation authority.
- The water-sector organization detected phishing payloads and quarantined infected hosts within minutes, which limited the red team’s ability to establish persistent command‑and‑control links.
- CISA traced the compromises to shared technical weaknesses: default Machine Account Quota, misconfigured AD CS templates (ESC1), cleartext or static cloud credentials, over‑permissioned Entra ID apps, no Conditional Access for workload identities, and no token‑revocation processes.
- The advisory urges concrete fixes—harden AD CS templates, set unused machine quotas to zero, remove stored cleartext keys, treat SCCM as a Tier 0 asset, enable Conditional Access for service identities, and improve alert tuning and cross‑SOC escalation—which, if adopted, could materially reduce risk to other critical‑infrastructure operators.