logo

CISA Credentials, Sensitive Data Exposed in GitHub Repository

ID: 66393c96-09eb-5ce0-8e85-d302b5dd5a63

STIX ID: report--66393c96-09eb-5ce0-8e85-d302b5dd5a63

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Jeffrey Burt

...
...

**Executive Summary:** A contractor for CISA publicly exposed sensitive CISA/DHS credentials and internal engineering artifacts in a GitHub repository for months — including AWS GovCloud admin keys, plaintext passwords, tokens, and build/deploy details — which persisted until researchers alerted the agency; the repository was taken offline and CISA reports no confirmed compromise, but the leak presented a high-risk window because some keys remained valid for 48 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.