Listen to this Post
Introduction: When the Attack Is Simulated, the Lessons Are Real
Cybersecurity exercises are supposed to reveal weaknesses before criminals do. But a recent red-team assessment by the Cybersecurity and Infrastructure Security Agency (CISA) delivered a particularly uncomfortable lesson: having security tools is not the same as having an effective defense.
In a rare public breakdown of its red-team activities, CISA described how its specialists tested two organizations—one in the government sector and another in the water sector. The results were striking. Attackers managed to penetrate both environments, but the organizations responded very differently once the intrusion began.
The government organization failed to effectively detect and respond to the simulated attack. CISA’s red team moved from compromised workstations to elevated privileges, sensitive business systems, cloud resources and other parts of the environment without being stopped.
The water organization, meanwhile, also suffered an initial compromise. Three employees were successfully tricked into clicking a malicious link. Yet the organization’s security operations team quickly recognized the suspicious activity, quarantined the affected machines and prevented the red team from freely continuing its original attack path.
That difference may be more important than the initial compromise itself.
The exercise demonstrates a reality that cybersecurity professionals have repeated for years: breaches are not always preventable, but uncontrolled breaches are often avoidable.
And as water facilities, government agencies and other critical infrastructure organizations remain attractive targets, the ability to recognize an intrusion and contain it rapidly could determine whether a cyberattack becomes a minor security incident or a serious operational crisis.
CISA Opens the Curtain on Its Red-Team Exercises
CISA does not frequently publish detailed accounts of its red-team operations. That makes this assessment particularly valuable for defenders because it provides an unusually direct look at how real-world defensive weaknesses can appear during an adversarial simulation.
The organizations were not publicly identified, and participation in the program was voluntary and conducted at the request of the organizations involved.
Rather than simply scanning systems for vulnerabilities, CISA’s red team attempted to behave like a determined attacker.
The objective was not merely to discover whether a phishing email could work. The exercise examined what could happen after the first foothold was established.
Could the attackers obtain higher privileges?
Could they move laterally?
Could they reach sensitive business systems?
Could they compromise cloud resources?
Could defenders detect the activity?
And perhaps most importantly, could defenders stop the intrusion before the attackers gained enough access to create meaningful damage?
The two organizations produced dramatically different answers.
Organization A: The Government Network That Did Not React
The first organization, identified only as Organization A, was a government-sector entity.
CISA began its simulated intrusion using an internal email address to deliver phishing messages. The campaign succeeded in giving the red team access to workstations.
At that point, the exercise could have ended with a simple conclusion: employees clicked a phishing message.
But that would have missed the larger problem.
The real danger emerged from what happened next.
Once inside, the red team worked to obtain elevated privileges and expand its access. It then moved laterally toward sensitive business systems and cloud resources.
The simulated attackers were effectively demonstrating a classic intrusion chain: initial access, privilege escalation, lateral movement and access to increasingly valuable assets.
The organization did not effectively interrupt that chain.
The Most Alarming Discovery Was Not the Phishing Attack
Phishing is hardly a new technique.
Organizations across the world spend enormous amounts of money trying to stop malicious emails, stolen credentials and social engineering attacks.
What made CISA’s findings particularly concerning was what happened after the phishing attack succeeded.
The red team was able to observe personnel emails within the organization’s security operations center. Those communications showed that endpoint detection and response systems were generating low- and medium-severity alerts.
The defenders were receiving warnings.
Yet they were not responding effectively to the simulated malicious activity.
This creates one of the most dangerous situations in modern cybersecurity: visibility without action.
An organization can deploy endpoint protection, security information and event management systems, cloud monitoring, identity controls and other defensive technologies.
But if analysts are overwhelmed by alerts, suspicious activity can disappear inside the noise.
Thousands of False Positives Created a Blind Spot
CISA identified an important contributor to Organization A’s failure: an enormous number of false-positive alerts.
Thousands of alerts were being generated, including some classified at higher severity levels.
When security teams receive too many warnings, the human ability to distinguish the truly dangerous events from harmless activity becomes increasingly difficult.
This is the cybersecurity equivalent of an alarm system that never stops ringing.
Eventually, people stop treating every alarm as an emergency.
That does not necessarily mean the security technology is broken. It means the surrounding detection and response process is not working effectively enough.
The result is alert fatigue.
And alert fatigue can become an
Organizational Silos Made the Problem Worse
CISA also pointed to organizational silos.
This is an underrated cybersecurity problem.
Security is rarely confined to a single team anymore. Identity management, cloud infrastructure, endpoint security, IT operations, networking, application teams and business departments all influence the security of the same environment.
When these groups operate independently, critical information can become fragmented.
One team may see suspicious authentication activity.
Another may notice an unusual endpoint event.
A third may observe strange cloud behavior.
Individually, none of those events may appear catastrophic.
Together, however, they can form a clear attack pattern.
The red-team exercise demonstrated why defenders must be able to connect those signals.
Organization B: The Water Sector Responds Differently
The second organization, Organization B, operated in the water sector.
CISA’s red team used a spearphishing campaign and successfully convinced three users to click a malicious link.
Again, the attackers obtained their initial foothold.
But the outcome changed almost immediately.
The
The affected workstations were quarantined in approximately 2, 10 and 20 minutes, respectively.
Those numbers are significant because cybersecurity defense is often a race against time.
The longer an attacker remains inside a network, the greater the opportunity to steal credentials, escalate privileges, discover valuable systems and establish persistence.
Organization B interrupted that progression.
Detection Changed the Entire Exercise
The water organization did not magically prevent the phishing attack.
It did something arguably just as important: it detected the attack and contained it.
Once the defenders recognized the compromise, the red team could no longer continue using the original attack path as if nothing had happened.
CISA therefore changed its approach.
The exercise moved into what is known as an assume-breach model.
Instead of pretending that the initial compromise had gone unnoticed, trusted agents within the organization provided CISA’s red team with access to a host that replicated the level of access the attackers would have possessed if defenders had failed to detect them.
This allowed CISA to continue testing the organization’s resilience without rewarding the defenders’ success by simply ending the exercise.
That distinction matters.
A good security assessment should not only ask whether attackers can enter.
It should ask what happens after defenders know they are there.
The Water Organization Was Tested Beyond the First Compromise
After receiving the simulated access, CISA attempted to escalate privileges and move laterally.
The red team reached sensitive business systems, cloud resources and eventually a bastion host inside the operational technology demilitarized zone.
That is where the organization once again detected suspicious activity.
The defenders isolated the system.
In other words, Organization B demonstrated something extremely important: detection and response remained active even after the exercise progressed into more advanced stages.
The organization still had weaknesses, but its defenders were capable of interrupting the attacker’s movement.
That difference fundamentally changes the risk profile.
Why Water Infrastructure Makes This Especially Important
The water sector has increasingly become a focus of cybersecurity warnings because digital systems now play a critical role in operating physical infrastructure.
Water and wastewater organizations can depend on IT systems, cloud services, remote access infrastructure, identity systems and operational technology environments.
That creates a complicated security ecosystem.
An attacker does not necessarily need to immediately manipulate industrial equipment to create problems.
They may first target employees.
Then identities.
Then administrative systems.
Then cloud resources.
Then privileged accounts.
Eventually, depending on the environment and the
That is why the separation between IT security and OT security cannot be treated as absolute protection.
A determined attacker will look for the bridge.
The Critical Lesson: Compromise Is Not the Same as Defeat
One of the strongest lessons from the CISA assessment is that organizations should stop measuring cybersecurity success solely by whether an attacker can get inside.
Modern networks are too complicated to assume that every intrusion can be prevented.
Employees will sometimes click malicious links.
Credentials will sometimes be stolen.
Software vulnerabilities will sometimes be exploited.
Cloud identities will sometimes be misused.
The real question becomes:
What happens next?
If an attacker enters and defenders identify the activity within minutes, quarantine affected systems and begin containment, the organization may still have a manageable incident.
If the attacker enters and spends hours or days moving through the environment without meaningful resistance, the consequences can be dramatically different.
The difference is not simply technology.
It is operational readiness.
Cloud Security Remains a Major Weakness
Despite the differences between the two organizations, CISA identified weaknesses shared by both.
One major issue was the underestimation of cloud risks.
This is increasingly important as organizations migrate critical applications, identities, workloads and data into cloud environments.
Cloud adoption can improve flexibility and scalability, but it also introduces new identities, APIs, authentication mechanisms, tokens, permissions and administrative pathways.
An attacker who compromises an identity can potentially move through cloud resources without ever touching a traditional corporate workstation.
That means cloud security must be treated as part of the core security architecture rather than an optional extension of endpoint defense.
Workload Identities Need Stronger Protection
CISA also highlighted the lack of Conditional Access controls for workload identities.
Conditional Access is commonly associated with controlling how human users authenticate and access resources.
But modern infrastructure increasingly relies on machine identities as well.
Applications, services, automation systems and cloud workloads can possess credentials and permissions that allow them to access valuable resources.
If those identities are poorly protected, an attacker who compromises them may inherit powerful capabilities without needing to compromise another employee.
This is an increasingly important area for defenders to examine.
Compromised Tokens Can Keep Attackers Alive
Another weakness identified by CISA was the absence of processes for revoking compromised access and refresh tokens.
Tokens can provide authenticated access without requiring users to repeatedly enter passwords.
That makes them convenient.
It can also make them valuable to attackers.
If a malicious actor obtains a valid authentication token, simply changing a password may not always be enough to immediately terminate the attacker’s access.
Organizations therefore need procedures for identifying compromised sessions and invalidating affected tokens.
Identity incident response must go beyond password resets.
Deep Analysis: Turning
1. Start With Endpoint Visibility
Security teams should verify that endpoint detection and response telemetry is actually reaching analysts in a usable form.
A basic Linux environment can begin with commands such as:
sudo journalctl --since "1 hour ago"
For active network connections:
ss -tulpn
For reviewing recently running processes:
ps aux --sort=-%cpu | head -20
These commands are simple, but they illustrate the principle: defenders need reliable visibility into what systems are doing.
2. Investigate Suspicious Authentication Activity
Identity events should be correlated with endpoint activity.
For example, defenders can investigate recent authentication events on Linux systems with:
sudo journalctl | grep -Ei "authentication|failed|accepted|sudo"
On Windows environments, security teams should review authentication events in Windows Event Viewer or through centralized logging and SIEM platforms.
The goal is not to manually search every machine.
The goal is to establish automated detection for unusual authentication behavior.
3. Reduce Alert Noise
A security operations center should regularly review the alerts being generated.
Teams should ask:
Which alerts are repeatedly false positives?
Which alerts are never investigated?
Which alerts should be correlated with identity activity?
Which alerts indicate lateral movement?
Which alerts require immediate isolation?
Which alerts can be safely automated?
Reducing noise is not about turning security alerts off.
It is about making important alerts impossible to overlook.
4. Build Automated Containment
Organizations should have predefined procedures for isolating compromised endpoints.
A useful response sequence can look like:
Alert
↓
Triage
↓
Validate compromise
↓
Isolate endpoint
↓
Disable or restrict compromised identity
↓
Revoke active sessions/tokens
↓
Investigate lateral movement
↓
Hunt for persistence
↓
Recover and monitor
The faster this process becomes, the less time attackers have to expand their access.
5. Treat Tokens as Security-Critical Assets
Security teams should include access and refresh tokens in incident-response procedures.
When an account is suspected of compromise, defenders should determine:
Which sessions are active?
Which tokens were issued?
Which devices used the identity?
Which applications accessed resources?
Which cloud workloads interacted with the account?
Password rotation alone should not automatically be considered sufficient containment.
6. Examine Cloud Identity Permissions
Organizations should inventory cloud identities and determine what each identity can actually access.
A useful security question is:
If this identity were stolen today, what could an attacker do with it?
If the answer includes sensitive business systems, administrative resources or privileged cloud infrastructure, that identity deserves additional protection.
Least privilege should apply to machines as well as humans.
- Separate IT and OT Without Assuming Isolation Is Perfect
Operational technology networks should be segmented and monitored.
Useful defensive controls include:
IT Network
|
Firewall / Controlled Gateway
|
DMZ
|
Bastion Host
|
OT Network
The objective is to make lateral movement difficult and observable.
Segmentation is not merely about blocking traffic.
It should also provide defenders with meaningful visibility when unexpected communication occurs.
- Test the Detection Process, Not Just the Firewall
A firewall test can answer whether a connection is blocked.
A red-team exercise asks a much more difficult question:
What happens when the attacker gets through?
Organizations should therefore conduct controlled simulations involving phishing, stolen credentials, privilege escalation, cloud compromise and lateral movement.
The exercise should measure detection and response times.
The difference between two minutes and two hours can be enormous.
9. Measure Mean Time to Detect
Organizations should establish measurable detection objectives.
For example:
Initial compromise detected: < 10 minutes Endpoint isolated: < 15 minutes Compromised account restricted: < 15 minutes Token/session response initiated: < 20 minutes Lateral movement investigation started: < 30 minutes
These are illustrative operational targets, not CISA requirements.
The important point is to turn cybersecurity from a vague promise into measurable performance.
10. Conduct Assume-Breach Exercises
CISA’s use of an assume-breach model provides a useful template.
Defenders should practice under the assumption that the attacker has already obtained valid access.
Then ask:
Can we detect privilege escalation?
Can we detect lateral movement?
Can we identify abnormal cloud access?
Can we isolate the affected system?
Can we revoke credentials?
Can we identify persistence?
Can we determine what the attacker accessed?
This type of exercise can reveal weaknesses that vulnerability scanning alone cannot.
The Human Element Remains Impossible to Ignore
The water organization suffered a successful phishing attack.
That fact is important because it demonstrates that even a security-conscious organization can have employees click malicious links.
Cybersecurity programs should therefore avoid framing every phishing incident as an individual employee failure.
The stronger approach is resilience.
Assume that somebody will eventually click.
Then design the environment so that one click does not automatically become a network-wide compromise.
That means endpoint protection, identity controls, segmentation, monitoring, rapid quarantine and well-rehearsed incident response all need to work together.
Security Tools Are Only as Good as the People Using Them
CISA’s findings also challenge the common assumption that purchasing better security technology automatically creates better security.
Organization A had security alerts.
The problem was that the alerts were buried among thousands of other events and were not effectively acted upon.
Organization B also experienced compromise.
The difference was its response.
This is why cybersecurity maturity cannot be measured solely by the number of products an organization owns.
A smaller security stack with disciplined monitoring and rapid response can sometimes outperform a massive collection of disconnected tools.
The SOC Is the Last Line Before an Intrusion Escalates
Security operations centers occupy a critical position in modern defense.
They are where scattered signals are supposed to become actionable intelligence.
An unusual login should not necessarily trigger panic.
But an unusual login followed by endpoint activity, privilege escalation and cloud access should immediately increase concern.
The
That requires good telemetry, useful detection rules, clear escalation procedures and analysts who know exactly what to do when a high-confidence alert appears.
CISA’s Findings Matter Beyond These Two Organizations
The two organizations tested by CISA should not be viewed as isolated examples.
Their experiences reflect broader challenges affecting government agencies, utilities and businesses.
Modern organizations increasingly operate hybrid environments containing traditional endpoints, cloud infrastructure, remote workers, SaaS applications, privileged identities and operational technology.
Every additional connection creates another potential pathway.
The challenge is no longer simply building a wall around the network.
The challenge is monitoring what happens across an enormous digital ecosystem.
What Undercode Say:
- Detection Speed Can Matter More Than Prevention
The biggest lesson from this exercise is that prevention is only one layer of security.
2. Organization B Did Not Avoid Compromise
Three users were successfully deceived, proving that no defense should depend entirely on perfect employee behavior.
3. But Organization B Limited the Damage
Rapid detection transformed a successful phishing attack into a contained security event.
4. Organization A Demonstrated the Opposite Problem
The government organization allowed the simulated attackers to continue expanding their access.
5. Alerts Are Worthless If Nobody Acts
A security dashboard filled with warnings does not automatically create security.
- Alert Fatigue Is a Real Operational Threat
Thousands of false positives can hide the events that actually matter.
7. Automation Should Help Analysts Prioritize
Security teams should automate repetitive triage wherever appropriate while preserving human judgment for complex incidents.
8. Organizational Silos Can Become Attack Surfaces
An attacker can exploit gaps between departments just as easily as technical vulnerabilities.
9. Security Teams Need Shared Visibility
Identity, endpoint, network and cloud telemetry should be correlated rather than analyzed in isolation.
- Cloud Infrastructure Deserves the Same Attention as Endpoints
An organization can have strong endpoint controls and still expose itself through weak cloud identity security.
11. Machine Identities Are Becoming More Important
Workloads and applications increasingly possess powerful permissions.
12. Machine Credentials Must Be Protected
A compromised service identity can become an extremely useful asset for an attacker.
- Token Revocation Should Be Part of Incident Response
Security teams need to know how to invalidate compromised authentication artifacts quickly.
- Password Resets Are Not the Whole Solution
Modern authentication attacks increasingly involve sessions, tokens and identity infrastructure.
- Water Infrastructure Cannot Treat OT as an Island
Operational technology may be separated from traditional IT, but the pathways connecting the environments must still be defended.
16. Bastion Hosts Need Serious Monitoring
Privileged systems connecting security zones should be treated as high-value assets.
17. Assume-Breach Testing Is Extremely Valuable
Organizations should practice defending themselves after the attacker has already obtained access.
18. Red Teams Expose Process Failures
The most damaging discovery is sometimes not a software vulnerability but a failure to respond.
19. Security Operations Need Measurable Objectives
Organizations should measure detection, containment and recovery times.
20. Mean Time to Detect Should Matter
Knowing how quickly an organization identifies suspicious activity can reveal defensive weaknesses.
21. Mean Time to Contain Matters Too
Detection without containment still leaves attackers room to operate.
22. Critical Infrastructure Needs Faster Response
A compromise affecting a business application is serious.
- A Compromise Affecting Operational Technology Can Be More Consequential
The potential impact can extend beyond data theft into physical operations.
24. Phishing Training Alone Is Not Enough
Training employees is useful, but resilient architecture assumes mistakes will happen.
25. Security Architecture Should Expect Failure
A strong design limits what happens after a user makes a mistake.
26. Segmentation Is a Damage-Control Mechanism
It can prevent one compromised machine from becoming a bridge to more sensitive environments.
27. Least Privilege Reduces the
The fewer unnecessary permissions an identity has, the fewer opportunities an attacker receives.
28. Cloud Permissions Should Be Regularly Reviewed
Old privileges can become forgotten pathways into sensitive resources.
29. False Positives Need Governance
Security teams should periodically examine which alerts consume analyst time without providing useful information.
30. High-Severity Alerts Must Remain Actionable
Severity labels are meaningless if everything is treated as urgent.
31. Detection Engineering Deserves Investment
Better detection rules can be more valuable than simply adding another security product.
32. Incident Response Must Be Practiced
A document sitting in an internal knowledge base is not the same as a rehearsed procedure.
- Red-Team Exercises Should Test Humans and Technology
A technical control can work perfectly while the organization still fails operationally.
34.
Publishing lessons from controlled assessments gives defenders a rare look at real-world defensive performance.
- The Results Should Not Become a Government-versus-Water Comparison
The exercise does not prove that water organizations are inherently more secure than government organizations.
36. It Demonstrates Different Defensive Outcomes
The most meaningful comparison is between response capabilities.
- Organization B Shows What Good Detection Looks Like
The defenders saw suspicious activity and acted before the red team could freely continue.
- Organization A Shows How Noise Can Become Dangerous
A flood of alerts can create an environment where important signals disappear.
39. Cybersecurity Is Ultimately About Resilience
Organizations will eventually face successful intrusion attempts.
- The Real Goal Is to Make the Attacker’s Victory as Difficult and Short-Lived as Possible
CISA’s exercise provides a powerful reminder: you do not need a perfect defense to stop a cyberattack from becoming a disaster—but you do need to know when you are under attack and act decisively.
✅ CISA Conducted Red-Team Assessments
The supplied report accurately describes CISA publicly discussing a red-team assessment involving two organizations.
The exercise was voluntary and conducted by request, while the participating organizations were not publicly identified.
✅ Both Organizations Experienced Initial Compromise
CISA’s assessment found that its red team successfully gained initial access to both environments.
The major difference was what happened after that initial compromise.
✅ The Water Organization Detected and Contained the Activity
Organization
CISA subsequently continued the assessment under an assume-breach model.
✅ The Government Organization Failed to Respond Effectively
Organization
Thousands of false positives and organizational silos were identified as contributing factors.
✅ Both Organizations Had Cloud and Identity Weaknesses
CISA identified weaknesses involving cloud risk, Conditional Access for workload identities and processes for revoking compromised access or refresh tokens.
These weaknesses demonstrate that strong endpoint detection alone is not sufficient for modern hybrid environments.
⚠️ The Exercise Does Not Prove That the Entire Government Sector Is Poorly Defended
The assessment involved a specific organization and should not be generalized to every government agency.
Likewise, the water organization should not be interpreted as representative of every water utility.
The strongest conclusion is that the exercise exposed specific weaknesses and demonstrated the value of rapid detection and containment.
Prediction
(+1) Detection-and-Response Investments Will Become More Important Than Ever
The cybersecurity industry is increasingly moving toward a resilience model in which organizations assume that some attacks will eventually bypass preventative controls.
As attackers become better at exploiting legitimate credentials, cloud identities and trusted applications, defenders will increasingly focus on detecting unusual behavior after initial access.
Organizations that can identify suspicious activity within minutes and automatically isolate affected assets will have a significant defensive advantage.
(+1) Assume-Breach Exercises Will Become More Common
Traditional penetration testing often concentrates on whether a vulnerability can be exploited.
Future security programs are likely to place greater emphasis on what happens after exploitation.
Red-team and assume-breach exercises can reveal weaknesses in monitoring, identity controls, incident response and communication that vulnerability scans cannot.
(+1) Cloud Identity Security Will Become a Board-Level Concern
As businesses and public institutions move more workloads into cloud platforms, identity will increasingly become the primary security perimeter.
Protecting human accounts will remain important, but protecting workload identities, tokens, service accounts and machine credentials will become equally critical.
(+1) Security Operations Centers Will Rely More Heavily on Automation
The alert-volume problem highlighted by CISA is unlikely to disappear.
Organizations will increasingly use automation and AI-assisted security operations to correlate events, reduce repetitive investigations and prioritize high-confidence threats.
The winning strategy will not necessarily be generating more alerts.
It will be generating fewer, better and more actionable alerts.
(-1) Organizations That Continue Treating Phishing as the Main Problem Will Remain Vulnerable
Phishing was the entry point in both simulations, but the deeper weakness was what happened afterward.
If organizations continue investing primarily in employee awareness while neglecting identity security, segmentation, token revocation, cloud monitoring and rapid containment, attackers will continue finding ways around the first layer of defense.
(+1) Water and Critical Infrastructure Security Will Receive Greater Scrutiny
The combination of IT, cloud infrastructure and operational technology makes critical infrastructure particularly sensitive to cyber risk.
CISA’s findings reinforce the argument that utilities need security programs capable of detecting attacks before adversaries can move from corporate environments toward operational systems.
The Bigger Warning Behind CISA’s Experiment
The most unsettling part of this story is not that CISA managed to penetrate two organizations.
That is exactly what a red team is supposed to attempt.
The real warning is that both organizations were compromised, yet only one demonstrated the ability to quickly recognize what was happening and fight back.
That distinction represents the future of cybersecurity.
Attackers do not need perfect execution forever. They only need one successful phishing message, one exposed credential, one vulnerable application or one poorly protected identity to get started.
Defenders, meanwhile, must build systems that assume mistakes will happen.
The water organization demonstrated what that philosophy can look like in practice. The phishing campaign worked. The initial compromise happened. But security operations detected the intrusion, isolated affected systems and forced the simulated attackers to change tactics.
The government organization faced a different outcome. The red team was able to move deeper into the environment while security alerts accumulated in the background.
That is the nightmare scenario for any security team.
The warning is simple:
A security alert that nobody investigates is almost as dangerous as having no alert at all.
And for organizations responsible for government services, water systems, cloud infrastructure or other critical operations, the difference between detecting an attacker in two minutes and discovering them after they have crossed the network may determine everything that happens next.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: cyberscoop.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




