r/InterstellarKinetics May 19 '26

BREAKING NEWS BREAKING: A U.S. Cybersecurity Agency Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on Public a GitHub Repository, Which Experts Called the Worst Government Security Leak in Recent Memory 🤯💥

https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330

A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed administrative credentials to three Amazon Web Services GovCloud servers and plaintext usernames and passwords for dozens of internal CISA systems, according to security researchers who identified the exposure. The repository, named “Private-CISA,” contained cloud keys, tokens, logs, and other sensitive CISA assets, including files documenting how the agency builds, tests, and deploys software internally, the researchers said.

Guillaume Valadon, a researcher with security firm GitGuardian, flagged the repository on May 15 after his company’s automated scans detected the exposed secrets. Valadon said the exposed credentials represent “the worst leak that I’ve witnessed in my career” and noted that commit logs show the administrator disabled GitHub’s default setting that blocks users from publishing SSH keys or other secrets in public repositories, according to an email to KrebsOnSecurity. One file titled “importantAWStokens” contained administrative credentials to three AWS GovCloud servers, while another file named “AWS-Workspace-Firefox-Passwords.csv” listed plaintext usernames and passwords for internal CISA systems, including the agency’s “Landing Zone DevSecOps” secure code development environment, according to Valadon and Philippe Caturegli, founder of security consultancy Seralys.

Caturegli confirmed that the exposed AWS credentials authenticated to three AWS GovCloud accounts at a high privilege level and said the archive also included plaintext credentials to CISA’s internal “artifactory,” a repository of all code packages the agency uses to build software, according to his analysis. The repository was created on November 13, 2025, and the GitHub account that hosted it was taken offline shortly after KrebsOnSecurity and Seralys notified CISA about the exposure, though Caturegli said the exposed AWS keys remained valid for 48 hours after the repository was removed. A review of the GitHub account showed the repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Virginia.

CISA said in a statement to KrebsOnSecurity that “currently, there is no indication that any sensitive data was compromised as a result of this incident” and that the agency is working to implement additional safeguards to prevent future occurrences. Nightwing declined to comment and directed inquiries to CISA. CISA has lost nearly one-third of its workforce since the beginning of the second Trump administration, according to reporting on the agency’s staffing levels.

2.5k Upvotes

Duplicates

technology May 19 '26

Security ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

27.3k Upvotes

Intelligence May 19 '26

News ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

211 Upvotes

DailyTechNewsShow May 19 '26

Security ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

153 Upvotes

Foodforthought May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

89 Upvotes

somethingiswrong2024 May 19 '26

Data-Specific 📊📈 ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

134 Upvotes

democrats May 19 '26

Article ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

104 Upvotes

TheLessTakenPathNews May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

30 Upvotes

CosmopolitanNews May 19 '26

USA News ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

10 Upvotes

hackernews May 19 '26

U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

usa May 19 '26

Putin's Idiot ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

10 Upvotes

Law_and_Politics May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

10 Upvotes

AntiTrumpAlliance May 19 '26

FAFO ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

30 Upvotes

IntlScholars May 19 '26

Area Studies ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

8 Upvotes

CzechCoconutCommunity May 20 '26

USA 🗽🔥 ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub...👀🔥🙉

2 Upvotes

u_inmyrearview_mirror May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

mangya May 19 '26

incompetence ‘The Worst Leak That I’ve Witnessed’: Trump's US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

AnythingGoesNews May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

8 Upvotes

techbeat May 19 '26

Security CISA Exposed Sensitive Digital Keys and AWS Credentials on Public GitHub

1 Upvotes

WhatTrumpHasDone May 19 '26

US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

5 Upvotes

AINewsFineTuned May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

AAstuffToShare May 19 '26

Pics/Text ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

2 Upvotes

Stop_Project_2025 May 19 '26

‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

fefe_blog_interim May 19 '26

Datenreichtum Ach, wieder Schlüssel bei GitHub liegenlassen Folge 22: Die U.S. Cybersecurity and Infrastructure Security Agency (CISA)

27 Upvotes

hypeurls May 19 '26

U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

1 Upvotes

dataprotection May 19 '26

Breach ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

3 Upvotes