Security2 distinct publishers3 min readPublished
Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The assume-breach pivot is the measurement. Once Organization B's defenders quarantined the systems compromised at initial access, CISA could not proceed on its own footing, so trusted agents inside the organisation handed the team a host built to replicate the access it would have held had nobody noticed [5]. Everything the advisory then records at Organization B, up to and including the bastion host in the OT demilitarized zone, ran on access the team was given rather than access it took [6][15]. That is the honest accounting of what one early catch bought: the earned portion of the intrusion ended at the first hop [15].
What it did not buy was an interior that held. Seated on an equivalent host, the same tradecraft arrived at the same classes of target in both organisations, sensitive business systems and cloud resources alike [16]. Organization B's second detection came at the OT DMZ, after that reach had already been demonstrated [6], and CISA notes it showed the ability to touch OT systems without actually doing so [11].
Organization A's entry is the part worth reading twice. Reconnaissance turned up a web application whose built-in accounts still carried default credentials, which let the team send mail from an internal address; phishing from that address put them on four workstations [7]. From there they ran a BloodHound collector modified to slip static EDR signatures while scraping users, computers, groups, access control lists, organisational units and group policy objects [8]. The customisation is the tell: endpoint detection and response was present enough at Organization A to be worth engineering around, and it produced nothing across initial access, domain-level privilege escalation and lateral movement to sensitive business systems and cloud [3][8][14]. One compromised workstation also sat at the default Machine Account Quota of 10, meaning unprivileged users could add computer accounts [9].
Set the two counts side by side. Organization B's defenders acted twice; Organization A's recorded nothing at all [14]. In the advisory's own framing of the divergence, the variable is defender action, detection followed by quarantine and later isolation, and not any stated difference in product inventory, headcount or spend [17]. The organisation that caught it was the water and wastewater one, and the one that did not was in government services and facilities [2][4].
CISA published the comparison with both assessed organisations' agreement, describing the activity, the defensive responses and the lessons for critical infrastructure [10]. The pairing is what makes it useful. Two engagements, similar tradecraft, one difference in outcome [1], and the difference lands on whether anyone was watching the first phished host rather than on how deep the intrusion could eventually go. Depth was available in both cases [16].
Ranked by verification strength, evidence, and original report placement.
CISA conducted two concurrent red team assessments using similar tradecraft and observed different defensive responses.
Organization A is a Government Services and Facilities Sector organization; Organization B is a Water and Wastewater Systems Sector organization.
At Organization A, the red team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to sensitive business systems and cloud resources undetected.
At Organization B, network defenders quickly detected the initial compromise and quarantined the affected systems.
Because Organization B detected the initial compromise, the red team moved to an assume breach model in which Organization B trusted agents provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity.
From the trusted-agent-provided host, the red team escalated privileges and moved laterally to sensitive business systems, cloud resources, and a bastion host in the OT demilitarized zone, where defenders again detected activity and isolated the system.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary government advisory with technique detail, corroborated by trade press
The central factual chain comes from CISA's own advisory with named techniques, ATT&CK v19 mapping and phase-by-phase narrative, and an independent trade outlet reproduces the key passages while adding SOC response timings and stated causes. Limits: the assessed organizations are anonymous, the published body is partial (mitigations section not in the supplied excerpt), and there is no third-party verification of the outcomes.
Two voluntary, anonymized engagements; no uptake data
Real-world grounding exists but is narrow: two critical infrastructure organizations that requested assessments, with concrete detection and quarantine behaviour recorded at one of them. Nothing in either source shows how widely the advisory's recommendations are being implemented, and no remediation follow-up is reported, so adoption is scored on the observed engagements alone.
Comparability slightly overstated; underlying facts hold
Every headline fact is supported by the primary advisory, so the gap is small. It is positive because both the trade framing ('water sector passes, government sector fails') and any same-tradecraft comparison beyond the first hop overstate like-for-like: at Organization B all post-initial-access activity ran from a host donated by trusted agents, and the OT objective was demonstrated rather than executed. The sample is also two anonymized, self-selected organizations, which limits sector-level conclusions.
Assessor publishes its own scorecard amid scrutiny of its red team
CISA is simultaneously the operator of the red team, the author of the advisory and the party whose red team capability has been publicly questioned; CyberScoop notes the agency denied laying off its red team after contractor exits and that such advisories are rare. The assessed organizations are anonymous and participated voluntarily, so favourable framing carries little cost and no external party can audit the results. Offsetting this, the advisory publishes an unflattering failure case in detail and maps activity to a public framework.
High confidence on facts, moderate on interpretation
Two independent publishers agree on the factual spine, and technique detail is specific and dated, so the factual claims are firm. Confidence is held below the top band because the sample is two anonymized organizations, the supplied advisory text is truncated before the mitigations and Organization B technical sections, and there is no independent verification or remediation follow-up.
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
CISA and the FBI put "exceptionally risky" software practices in writing, and buyers get the list1 distinct publisher
security
FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026
1 article · August 25, 2026