← Back
OtherCISA Advisories·3 hours ago

A Tale of Two SOCs: Insights From Two Red Team Assessments

CISA conducted simultaneous red team assessments at two critical infrastructure organizations, revealing stark differences in detection and response capabilities. While both organizations experienced full domain compromise and cloud access, Organization A failed to detect the red team's activity due to alert fatigue and organizational silos, whereas Organization B quickly identified and contained initial compromises through tuned detection tools and empowered security staff. Common weaknesses in both organizations—including excessive cloud application permissions, long-lived credentials, misconfigured Active Directory Certificate Services, and inadequate token revocation procedures—enabled persistence and lateral movement, highlighting the critical need for baseline establishment, inter-team communication, and mature cloud security processes.

Read full article at CISA Advisories

Related Articles

OtherInfosecurity Magazine·1 hour ago

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens is a phishing platform that enables attackers to conduct real-time control of compromised victim sessions, targeting credentials and sensitive data from 53 financial institutions. The platform's live-steering capability allows operators to dynamically adapt phishing attacks as they unfold, significantly increasing their effectiveness against financial sector targets.

OtherCyberScoop·1 hour ago

Interpol targets Black Axe’s illicit financial web in latest international sting

Interpol coordinated a multi-country operation targeting Black Axe's financial networks, resulting in the seizure of millions in assets and disruption of Crime-as-a-Service infrastructure operating across four continents. The sting represents a significant international effort to dismantle the group's illicit financial operations and underlying criminal infrastructure.

OtherSecurityWeek·1 hour ago

Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails

Alice, formerly ActiveFence, has secured $140 million in new funding to advance its AI model defense and enterprise guardrail capabilities, bringing its total funding to $280 million. The investment will support the company's efforts to expand protections for AI systems against misuse and harmful outputs in enterprise environments.