logo

CISA Contractor Exposed Sensitive Credentials in Public GitHub Repository

ID: 57c89654-346c-59f1-be36-72de1bfa90fa

STIX ID: report--57c89654-346c-59f1-be36-72de1bfa90fa

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

Author: Joseph Ofonagoro

...
...

A contractor for CISA accidentally exposed highly privileged credentials, plaintext passwords, cloud keys (including AWS GovCloud tokens), logs, and deployment/configuration files in a public GitHub repository; CISA removed the repo and is investigating while asserting there is no indication of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.