CISA Admin Exposes AWS GovCloud Credentials on GitHub
ID: ffb72de5-92d4-579e-a85a-bbdeda92e937
STIX ID: report--ffb72de5-92d4-579e-a85a-bbdeda92e937
Feed Name: Cyber Press
A Nightwing contractor for CISA publicly exposed highly privileged AWS GovCloud admin keys, plaintext internal usernames/passwords, DevSecOps (LZ-DSO) and Artifactory credentials in a GitHub repository that remained accessible from November 13, 2025 until mid-May 2026. Independent researchers validated the credentials, warned the artifactory and build-pipeline access could enable persistent supply-chain backdoors, and noted exposed keys remained valid for ~48 hours after takedown while CISA investigates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
