threat-intel
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
High
Summary
CISA conducted two red team assessments against two critical infrastructure organizations, revealing vastly different defensive capabilities. Organization A was completely compromised at the domain level, with no detection of the attack, due to a combination of poor security practices and a lack of effective monitoring and incident response. Organization B, however, detected and contained the initial phishing attempts, preventing further intrusion and limiting the scope of the attack.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
