logo

America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames

ID: fe1d3003-ab25-5895-9b28-9b5adfad2af4

STIX ID: report--fe1d3003-ab25-5895-9b28-9b5adfad2af4

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-21

...
...

A public GitHub repository named “Private-CISA” containing roughly 844 MB of production infrastructure material and numerous plaintext secrets (passwords, private keys, tokens, AWS/Azure credentials, Kubernetes manifests, Terraform, GitHub tokens, Entra ID SAML certs, etc.) was discovered and reported on May 14; CISA removed the repository the next day. The leak persisted for approximately six months, included obvious filenames and an explicit guide to disable GitHub secret scanning, and created multiple high-impact attack paths including destructive operations, long-term persistence in build/deploy pipelines, and credential-driven access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.