In stunning display of stupid, secret CISA credentials found in public GitHub repo
ID: 7eba0f1b-c25f-5ed5-ad16-61aed262cfbd
STIX ID: report--7eba0f1b-c25f-5ed5-ad16-61aed262cfbd
Feed Name: Security - Ars Technica
Threat Score
A public GitHub repository called "Private-CISA" reportedly exposed plaintext passwords, SSH private keys, tokens, and other sensitive CISA assets since at least November 2025; repository secret-detection protections were disabled. Security researchers (GitGuardian and Seralys) found the repo, and testing demonstrated the included credentials allowed high-privilege access to multiple AWS GovCloud accounts; the repo appears linked to a CISA contractor named Nightwing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
