logo

In stunning display of stupid, secret CISA credentials found in public GitHub repo

ID: 7eba0f1b-c25f-5ed5-ad16-61aed262cfbd

STIX ID: report--7eba0f1b-c25f-5ed5-ad16-61aed262cfbd

Feed Name: Security - Ars Technica

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-22

Author: Lee Hutchinson

...
...

A public GitHub repository called "Private-CISA" reportedly exposed plaintext passwords, SSH private keys, tokens, and other sensitive CISA assets since at least November 2025; repository secret-detection protections were disabled. Security researchers (GitGuardian and Seralys) found the repo, and testing demonstrated the included credentials allowed high-privilege access to multiple AWS GovCloud accounts; the repo appears linked to a CISA contractor named Nightwing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.