@brian_greenberg@infosec.exchange
Post #3360324
2026-05-19 16:33 UTC
🥶 A contractor for CISA posted AWS GovCloud admin keys to a public GitHub repo! The repo was named "Private-CISA." Not an accident, the contractor actively disabled GitHub's built-in secret scanner to do it. That's a choice. Not a typo, not a misconfiguration. Someone turned off the guardrail and then stored plaintext credentials in a file called "importantAWStokens." That should make every security leader lose their 💩 AND the exposed keys stayed valid for 48 hours after CISA was notified. The agency responsible for protecting the country's critical infrastructure took two days to rotate credentials sitting in a public repo. 🤬 One researcher called this "the worst leak I've witnessed in my career." The exposed files included credentials to CISA's internal software build environment. Anyone who found those keys first could have backdoored the packages CISA builds and deploys. Every new build would carry that backdoor forward. CISA has lost nearly a third of its workforce since January. The oversight that might have caught this sooner is gone.
Two questions worth taking back to your own team:
・ When did you last verify that secret scanning is actually enabled across every repo your contractors touch?
・ If you got the call today that credentials were public, how long would it take to rotate them?
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
#CISA #CloudSecurity #SupplyChainSecurity #CyberGovernance #security #privacy #cloud #infosec
Replies (0)
No replies.