Data Breaches · Credential Theft

CISA Repo Leak Reaches Cloud and Pipeline Access

The dangerous part is not just leaked cloud keys. The same public repo also exposed internal build, test, and deploy material, so a secret leak becomes a path into CISA’s cloud and delivery systems, not just a password-rotation issue.

The public GitHub repository, "Private-CISA," was tied to a CISA contractor and contained privileged AWS GovCloud credentials plus internal CISA/DHS secrets, tokens, plaintext passwords, logs, and deployment documentation. Reporting says the exposed material included administrative access to multiple AWS GovCloud servers and files describing how CISA software is built, tested, and deployed.

If those credentials were still usable, an attacker could move from GitHub exposure into internal cloud and CI/CD infrastructure. The risk persists even after secret rotation if the exposed build and deploy documentation helps an attacker understand and weaponize the environment.

8 sources · May 22

Timeline

Sources

Part of the PlainSec briefing for 2026-05-19

Every edition of this story: CISA Repo Leak Reaches Cloud and Pipeline Access

More from today