
CISA Red Team Advisory Shows What Fast Detection Buys
CISA's new advisory compares two red team assessments where one SOC contained the intrusion in 2 to 20 minutes, and explains what made the difference.
Security advisories usually tell you what went wrong. CISA's August 25, 2026 release, tracked as AA26-237A and titled A Tale of Two SOCs, does something more useful: it runs the same attack against two organisations and shows what made one of them stop it in minutes. That comparison is the most actionable defensive artefact published this month.
- CISA ran two simultaneous red team assessments using similar tradecraft against two critical infrastructure organisations, referred to as Organization A and Organization B
- Organization B's defenders identified the initial phishing payloads as they executed and isolated the affected workstations within 2 to 20 minutes, cutting command-and-control before lateral movement
- Both organisations shared the same underlying misconfigurations, including a default Machine Account Quota and a misconfigured Active Directory Certificate Services template
- CISA's stated conclusion is that detection tools are only as effective as the people, processes and procedures supporting them
What Organization B Did Right
Start with the win, because it is reproducible. Organization B's security team caught the phishing payloads at execution time, not at exfiltration time, and moved straight to isolation. Quarantining the affected workstations within a 2 to 20 minute window severed the command-and-control channel before the red team could pivot, which meant the entire rest of the attack chain never got to run.
The specific number matters less than the shape of it. What this team had was a clear escalation path and analysts with the authority to isolate a machine without convening a meeting. Detection that arrives fast but lands in a queue awaiting approval is functionally the same as no detection at all. The organisational design here, not a superior product, is what produced the outcome.
Why Did the Other SOC Miss the Same Attack?
CISA is unusually specific, and every cause is fixable. Thousands of false-positive alerts generated by normal business operations, many rated at higher severity than the genuine ones, buried the red team's activity in noise. Multiple security operations centres and endpoint tools ran without shared visibility, so no single view of the intrusion ever assembled. Analysts had no defined escalation procedure and limited authority to act.
The most instructive detail is a real alert on an SCCM server, tied directly to red team activity, that was dismissed as a false positive because nobody could determine who owned the system. That is an asset inventory failure presenting as a detection failure, and it is one of the most common patterns in enterprise security. If your responders cannot identify a system's owner within minutes, alerts on that system will be closed rather than chased.
The Shared Misconfigurations Worth Auditing This Week
Both organisations exposed the same privilege escalation path, and it is a good weekend checklist. The default Machine Account Quota in Active Directory lets any authenticated user add machine accounts to the domain, and it remains at its permissive default in a large share of environments. Paired with a misconfigured Active Directory Certificate Services template, that combination gives an attacker a route to domain-wide privileges, the same certificate-template abuse class behind recently disclosed domain-takeover techniques.
Initial access in Organization A came from something even simpler: a web application still carrying default credentials on several built-in accounts, which let the red team send phishing mail from a genuine internal address. Default credentials, permissive AD defaults and unclear asset ownership are unglamorous, and they are also free to fix.
Turning the Advisory Into a Plan
The practical takeaway is that alert tuning is a security control, not housekeeping. A SOC drowning in high-severity false positives has effectively disabled its own detection layer, and reducing that noise is usually cheaper than any new tool. Pair that with documented escalation authority and a current asset inventory, and you have most of what separated the two outcomes here.
It also lands alongside a strong month for defensive tooling, including Mandiant's agents finding 100 critical flaws in two days and Fortinet's move into AI agent red-teaming. Automation keeps improving, but this advisory is a reminder that response authority is still a human design decision. More defensive coverage is on our AI security page.
Sources: CISA Advisory AA26-237A — August 25, 2026; The Hacker News — August 25, 2026; CISA Newsroom — August 25, 2026.
More Ai Security Stories

WhatsApp Passkeys Go Multi-Device for 1 Billion Users
WhatsApp now supports multiple passkeys per account, upgrades its six-digit PIN to a full password, and adds caller context on Android.

Microsoft Teams Blocks External Meeting Bots by Policy
A new Microsoft Teams admin policy automatically blocks identified external meeting bots, with general availability due by late September 2026.

Fortinet Buys Virtue AI to Red-Team Your AI Agents
Fortinet acquired Virtue AI on August 17, adding agentic red-teaming across 50 sandboxed environments and 1,000 risk categories to its security fabric.
