
CISA red-teamed two organisations the same way — one saw nothing, the other cut them off in two minutes
2026-08-27Security
Advisory AA26-237A describes simultaneous red team assessments using similar tradecraft against a government services body and a water utility. Both were compromised at the domain level. One detected each phishing payload as it executed and isolated the machines within 2 to 20 minutes. The other saw nothing, and the red team read its security team's email to check.