⚠JUST IN: Update related to the credential leak involving CISA (US Cybersecurity Agency)
It has come to light, that even though CISA claimed last week, that they're actively working on securing and replacing leaked secrets; an exposed RSA private key, that could grant an unauthorized user full access with full administrative rights to a GitHub app, which contains the entire CISA-IT GitHub organization with all code repos, was still valid.
Dylan Ayrey, founder of a company "TruffleHog", that works on identifying exposed secrets on GitHub, notified a renowned cybersecurity specialist Brian Krebs, who notified CISA of Ayrey's findings. As of now, CISA has invalidated the leaked RSA private key, but according to Ayrey, CISA has not yet changed the leaked credentials to various other sensitive security infrastructure. Situation is delicate due to the fact, that ill ridden advesaries could've seen CISA's secrets and critical infrastructure months ago.
US Congress has also joined the scandal, demanding answers from CISA's leadership.
@arch
Post #24
1.17K
Arch ⚠JUST IN: Researchers found sensitive credentials belonging to CISA (US Cybersecurity Agency) stored in a public GitHub repository A firm called "GitGuardian" that scans public GitHub repositories for poorly kept secrets, made a discovery regarding CISA's…
- ❤ 2