Violazioni · 131 giorni fa
La parte pericolosa non sono solo le chiavi cloud esposte. Lo stesso repo pubblico ha anche esposto materiale interno di build, test e deploy, quindi una perdita di segreti diventa un percorso verso i sistemi cloud e di delivery di CISA, non solo un problema di rotazione delle password.
8 fonti che coprono questa storia
CISA Security Leak - Schneier on Security
Crazy story: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.
CISA credential leak raises alarms, and Capitol Hill demands answers
Congressional Democrats demand answers after a CISA credential leak on GitHub exposed privileged AWS GovCloud accounts and internal agency systems.
CISA Exposes Secrets, Credentials in 'Private' Repo
The agency's GitHub repository, publicly available since November 2025, was ironically named "Private-CISA."
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
Secret CISA credentials found in public GitHub repo
SSH keys, plaintext passwords, other sensitive data had been up since November 2025.
Contractor’s public GitHub account exposed GovCloud and CISA credentials
‘This kind of exposure happens with alarming frequency,’ said an expert; here’s what CSOs and CIOs should do to protect employees’ and contractors’ GitHub repositories.
US cyber agency CISA exposed reams of passwords and cloud keys to the open web | TechCrunch
The federal cybersecurity agency left plaintext passwords in a spreadsheet uploaded to a public GitHub repository, per a report by independent journalist Brian Krebs.
CISA Admin Leaked AWS GovCloud Keys on Github
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.
Part of the PlainSec briefing for 2026-05-19