logo

Lessons Learned from CISA’s Recent GitHub Leak

ID: a28e2a71-584f-5fd7-8cf4-498292b5e7e9

STIX ID: report--a28e2a71-584f-5fd7-8cf4-498292b5e7e9

Feed Name: Krebs on Security

Threat Score
65/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: BrianKrebs

...
...

CISA published a postmortem after a contractor left 844 MB of sensitive agency data — including AWS GovCloud admin keys and plaintext internal credentials — in a public GitHub repository for about six months; GitGuardian notified CISA, which took over 48 hours to rotate keys, and the agency reports no evidence the leaked credentials were used externally while outlining remediation steps (key rotation, access revocation) and recommendations for continuous secrets scanning and clearer researcher reporting channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.