logo

CISA Admin Exposes AWS GovCloud Credentials on GitHub

ID: ffb72de5-92d4-579e-a85a-bbdeda92e937

STIX ID: report--ffb72de5-92d4-579e-a85a-bbdeda92e937

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Lucas Martin

...
...

A Nightwing contractor for CISA publicly exposed highly privileged AWS GovCloud admin keys, plaintext internal usernames/passwords, DevSecOps (LZ-DSO) and Artifactory credentials in a GitHub repository that remained accessible from November 13, 2025 until mid-May 2026. Independent researchers validated the credentials, warned the artifactory and build-pipeline access could enable persistent supply-chain backdoors, and noted exposed keys remained valid for ~48 hours after takedown while CISA investigates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.