America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
ID: 7520a7d6-ba1c-5fa8-bbe8-2714af3ebf05
STIX ID: report--7520a7d6-ba1c-5fa8-bbe8-2714af3ebf05
Feed Name: The Register (Security)
Threat Score
A public GitHub repository titled "Private-CISA" exposed roughly 844 MB of sensitive CISA infrastructure data for about six months, including plaintext passwords, private keys, AWS and Azure credentials, GitHub tokens, Kubernetes manifests, Terraform code, and SAML certificates; the leak was discovered by a GitGuardian researcher on May 14 and the repository was taken offline the following day with CISA stating there is currently no indication of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
