Lawmakers Demand Answers as CISA Tries to Contain Data Leak
ID: ab79fe7e-3205-5d4f-9f3d-ba048966c68b
STIX ID: report--ab79fe7e-3205-5d4f-9f3d-ba048966c68b
Feed Name: Krebs on Security
Threat Score
**CISA credential leak:** A CISA contractor published plaintext credentials and an RSA private key in a public GitHub repository called `Private-CISA`, exposing AWS GovCloud tokens and other internal secrets; the exposed key could grant broad access to CISA’s GitHub organization and CI/CD pipelines. CISA reported it is responding and rotating credentials, but remediation remained incomplete, prompting congressional inquiries and concerns about potential adversary access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
