Build Repos Leak Live Cloud Keys

The break is in what teams store inside a build repository, not in the source tree itself. In CISA’s case, a contractor copied a build and deployment repo to a personal GitHub account, and that bundle included administrator and build credentials plus Infrastructure as Code data that held AWS GovCloud keys. CISA says logs showed no authorized use of the leaked credentials and no customer or mission data exposure. The point is that IaC and deployment artifacts can carry working secrets, so a repo copy can move cloud-admin access out of the controlled environment and into a personal account.

Part of the PlainSec briefing for 2026-07-13

Sources