CISA advisory highlights detection gaps after dual red-team assessments
Issued Aug. 25 2026, the advisory directs federal, state, local and critical-infrastructure entities to adopt its mitigation steps immediately.

The Cybersecurity and Infrastructure Security Agency released a cybersecurity advisory describing findings from two simultaneous red-team assessments and outlining mitigation actions that apply to Federal Civilian Executive Branch agencies, state, local, tribal and territorial governments, and critical-infrastructure owners.
In Organization A, a Government Services and Facilities sector entity, the red team gained initial access through a web application with default credentials, sent phishing emails, and compromised four workstations. Using a modified BloodHound collector, the team scraped Active Directory data, exploited a default Machine Account Quota of 10 to add computer accounts, and leveraged misconfigured AD Certificate Service templates to request certificates for newly created machine accounts. The team then harvested cleartext credentials and long-lived AWS IAM keys to obtain administrative access to multiple sensitive business systems and cloud resources without any defensive intervention.
Organization B, a Water and Wastewater Systems sector entity, detected the initial compromise attempts, isolated the affected systems, and forced the red team into an assume-breach model. Defenders again identified activity when the team moved laterally to a bastion host in the OT demilitarized zone, enabling rapid containment.
The advisory cites untuned detection tools, organizational silos, and underestimated cloud risks as primary contributors to the divergent outcomes. Recommended actions include establishing and continuously maintaining a baseline, reducing alert noise through fine-tuning, breaking down silos and empowering network defenders, implementing Conditional Access policies for workload identities, and regularly reviewing procedures for detecting, revoking and rotating access tokens after a cloud compromise.
CISA urges all covered entities to adopt the listed mitigations to reduce the likelihood and impact of malicious cyber incidents. The full advisory and technical details are available in the PDF released on August 25, 2026.
Further reading


