⚠JUST IN: Researchers found sensitive credentials belonging to CISA (US Cybersecurity Agency) stored in a public GitHub repository
A firm called "GitGuardian" that scans public GitHub repositories for poorly kept secrets, made a discovery regarding CISA's publicly available sensitive logins.
Suggestions indicate, that the scandal originated from a third-party contractor, related to CISA and DHS (Department of Homeland Security), and possibly happened due to human error. The repository was created back in Nov 2025, and has been fully accessible to the public all this time. Over the year, multiple commits have been made to the files within in the repo, one of them being an automated feature that warns the owner of potential leaks.
Bad security led to the following data to be exposed: credentials and passwords for internal infrastructure, logs, AWS tokens and cloud keys. AWS tokens exposed logins to 3 GovCloud servers (AWS environment that is specifically designed for US government).
CISA responded with a public statement saying, that the credentials weren't manipulated in any way, so no citizen data was compromised.
As of now, CISA has made the repository private, denying any further access to possible threat actors.
@arch
Post #18
1.05K

- ❤ 2
- 🐳 1