AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons
ID: 4dc0dcce-5b4b-55d9-9711-3709d8831e05
STIX ID: report--4dc0dcce-5b4b-55d9-9711-3709d8831e05
Feed Name: GBHackers
Threat Score
CISA disclosed that an employee contractor's public GitHub repository contained Infrastructure-as-Code, build automation scripts, and exposed administrative credentials for AWS GovCloud and numerous internal systems. The agency immediately took the repository offline, revoked access, rotated credentials across affected environments, and strengthened repository controls and incident response playbooks; investigators found no evidence of external misuse or customer data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
