Two SOCs, Same Attack, Opposite Outcomes (08/26/2026)

August 26, 2026
Two SOCs, Same Attack, Opposite Outcomes (08/26/2026)
Key Intel / TL;DR
  • CISA advisory AA26-237A documents simultaneous red team assessments of two critical infrastructure organizations using similar methods.
  • One SOC isolated each phishing payload within 2 to 20 minutes; the other never detected a full domain compromise that reached the security team's own email.
  • CISA's conclusion is that detection tools are only as good as the people and processes behind them.
  • CISA observed activity against more than 100 internet-exposed water and wastewater systems in July, across at least a dozen states, mostly small rural utilities.
  • The FBI seized QScan and QTRouter, tooling a China-linked contractor used against NASA, the Federal Reserve, the Senate, and others.

Read advisory AA26-237A before anything else this week. CISA ran red team assessments against two critical infrastructure organizations at the same time using similar methods, and the outcomes were so far apart that the agency titled the writeup a tale of two SOCs. The useful part is that the difference was not the tooling.

Top 5 Critical Security Alerts

1. One SOC Caught It in Minutes, the Other Saw Nothing

At Organization B, a water and wastewater utility, the security operations center detected each phishing payload as it executed and isolated the affected workstations within 2 to 20 minutes, preventing lateral movement. The team later reached a domain service account through SCCM and an OT bastion host, but outbound internet blocking stopped them establishing command and control. At Organization A, in government services and facilities, the red team walked from a web application with default credentials to full domain compromise, escalating through Machine Account Quota settings and misconfigured Active Directory Certificate Services templates, harvesting cleartext credentials from database configuration files and static AWS keys set never to expire, and finally abusing Entra ID applications with elevated permissions to read the security team’s email. Nothing was detected. The Hacker News

Operator Note: CISA’s own framing is that detection tools are only as effective as the people, processes, and procedures supporting them, and the two organizations are the controlled experiment that proves it. The specific findings at Organization A are all inventory problems rather than exotic ones: a default credential, a certificate template nobody reviewed, and cloud keys with no expiry. Read the advisory and check those three against your own estate this week.

2. Over 100 Water Systems Were Targeted in July

CISA has confirmed it observed malicious activity against more than 100 internet-exposed systems in the water and wastewater sector during July, across at least a dozen states including Minnesota, Michigan, Georgia, South Dakota, and New Jersey. The targets were mostly small rural utilities running programmable logic controllers connected directly to cellular modems. The federal government has not formally attributed the campaign, though analysts widely suspect Iranian affiliation, and one characterised the activity as test runs for something larger. The Register

Operator Note: A PLC on a cellular modem is a control system with a public address and no perimeter in front of it, which is the configuration our article yesterday on operator displays assumed an attacker would need to work for. The advisory’s first mitigation is still to get these off the internet, and for a utility with two staff and no security budget that is a procurement problem rather than a technical one. TechCrunch

3. The FBI Seizes a Chinese Contractor’s Scanning and Proxy Tools

The Department of Justice and FBI announced the seizure of QScan, which scans and automatically infects internet-connected devices worldwide, and QTRouter, an obfuscation network built from compromised devices and leased virtual private servers. The tooling is attributed to a group linked to Nanjing Xinjiuwei Network Technology Company, active since May 2018 and associated with China’s Ministry of State Security. Targets included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, Health and Human Services, the National Institutes of Health, and the US Senate. The Hacker News

Operator Note: QTRouter is the part worth understanding, because it blended malicious traffic with legitimate proxy services to make the source look ordinary. Your egress monitoring is looking for connections to bad places, and this design means the connection goes to an unremarkable one. The compromised devices doing the routing belonged to organizations that had no idea they were infrastructure. The Record

4. Boston Scientific Reports Global Disruption From an Ongoing Attack

The medical device manufacturer has disclosed a cyberattack causing global disruption to its operations, with shipment processes specifically affected. The incident is ongoing. The Record

Operator Note: The word to note in that disclosure is shipment, because it puts the consequence in the physical world rather than in a data set. When a device manufacturer cannot ship, the downstream effect lands in hospitals that scheduled procedures around delivery dates, and none of those hospitals had a vendor risk process that modelled this. BleepingComputer

5. NovaCookies Rents Microsoft 365 Session Theft for $320 a Month

The kit abuses genuine Docusign notifications to steal Microsoft 365 sessions, which means the delivery vehicle is a real email from a real service the recipient has legitimately used before. Dark Reading

Operator Note: This is the third session-theft campaign we have carried this month after Mirage2FA and ZeroTokens, and the pricing is the detail that should worry you. At $320 a month the economics no longer require a skilled operator or a large target, so the selection criteria that used to keep mid-market companies out of scope have stopped applying. The Hacker News

Additional Security Alerts

Vulnerabilities & Exploits

  • A critical Avada WordPress theme flaw allows zero-click remote code execution: Themes are code, and this one ships on a very large number of sites. BleepingComputer
  • GPUThor defeats NVIDIA ECC protection to gain root: Memory error correction being turned into an attack path. BleepingComputer
  • Unpatched Kaltura mwEmbed flaws allow remote file reads and code execution: The Hacker News

Security Breaches & Incidents

  • The Carhartt breach affects 12.9 million people, half what the actors claimed: Troy Hunt’s writeup on verifying breach claims is the more useful read. The Register
  • Interpol Operation Jackal IV identified 263 suspects and arrested 58: Infosecurity Magazine

Threat Intelligence

  • Iran-linked operators are expanding infrastructure across Europe and the Middle East: The Record
  • Four in five AI tools run with no IT oversight: Shadow AI as an inventory problem before it is a policy one. Infosecurity Magazine

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)