The dangerous part is not just leaked cloud keys. The same public repo also exposed internal build, test, and deploy material, so a secret leak becomes a path into CISA’s cloud and delivery systems, not just a password-rotation issue.
The public GitHub repository, "Private-CISA," was tied to a CISA contractor and contained privileged AWS GovCloud credentials plus internal CISA/DHS secrets, tokens, plaintext passwords, logs, and deployment documentation. Reporting says the exposed material included administrative access to multiple AWS GovCloud servers and files describing how CISA software is built, tested, and deployed.
If those credentials were still usable, an attacker could move from GitHub exposure into internal cloud and CI/CD infrastructure. The risk persists even after secret rotation if the exposed build and deploy documentation helps an attacker understand and weaponize the environment.
Crazy story: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.