US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals
ID: ad140298-98ab-5237-9a18-64df94f72172
STIX ID: report--ad140298-98ab-5237-9a18-64df94f72172
Feed Name: TechCrunch Security News
CISA lacked a prepared incident-response playbook after a contractor accidentally uploaded sensitive access keys and credentials to a public GitHub repository; a security researcher and journalist notified the agency, which removed the repository and revoked the credentials. The postmortem noted no customer or mission data was exposed, criticized unclear channels for researchers to report incidents, and tied the agency's response shortfalls to staffing and leadership gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
