CISA Broke Into a US Federal Agency, No One Noticed For a Full 5 Months

Summary:

  1. A 2023 CISA red team exercise exposed critical security failings in a US federal agency, leading to a full domain compromise.

  2. The team exploited an unpatched vulnerability, conducted phishing attacks, and found weak passwords and unsecured credentials, gaining access to tier zero assets.

  3. The agency failed to detect or remediate malicious activity for five months, highlighting the need for defense-in-depth principles and improved security measures.

Read more on The Register

1 Like