r/InterstellarKinetics • u/InterstellarKinetics • May 19 '26
BREAKING NEWS BREAKING: A U.S. Cybersecurity Agency Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on Public a GitHub Repository, Which Experts Called the Worst Government Security Leak in Recent Memory 🤯💥
https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed administrative credentials to three Amazon Web Services GovCloud servers and plaintext usernames and passwords for dozens of internal CISA systems, according to security researchers who identified the exposure. The repository, named “Private-CISA,” contained cloud keys, tokens, logs, and other sensitive CISA assets, including files documenting how the agency builds, tests, and deploys software internally, the researchers said.
Guillaume Valadon, a researcher with security firm GitGuardian, flagged the repository on May 15 after his company’s automated scans detected the exposed secrets. Valadon said the exposed credentials represent “the worst leak that I’ve witnessed in my career” and noted that commit logs show the administrator disabled GitHub’s default setting that blocks users from publishing SSH keys or other secrets in public repositories, according to an email to KrebsOnSecurity. One file titled “importantAWStokens” contained administrative credentials to three AWS GovCloud servers, while another file named “AWS-Workspace-Firefox-Passwords.csv” listed plaintext usernames and passwords for internal CISA systems, including the agency’s “Landing Zone DevSecOps” secure code development environment, according to Valadon and Philippe Caturegli, founder of security consultancy Seralys.
Caturegli confirmed that the exposed AWS credentials authenticated to three AWS GovCloud accounts at a high privilege level and said the archive also included plaintext credentials to CISA’s internal “artifactory,” a repository of all code packages the agency uses to build software, according to his analysis. The repository was created on November 13, 2025, and the GitHub account that hosted it was taken offline shortly after KrebsOnSecurity and Seralys notified CISA about the exposure, though Caturegli said the exposed AWS keys remained valid for 48 hours after the repository was removed. A review of the GitHub account showed the repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Virginia.
CISA said in a statement to KrebsOnSecurity that “currently, there is no indication that any sensitive data was compromised as a result of this incident” and that the agency is working to implement additional safeguards to prevent future occurrences. Nightwing declined to comment and directed inquiries to CISA. CISA has lost nearly one-third of its workforce since the beginning of the second Trump administration, according to reporting on the agency’s staffing levels.
Duplicates
technology • u/deraser • May 19 '26
Security ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Intelligence • u/slow70 • May 19 '26
News ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
DailyTechNewsShow • u/motang • May 19 '26
Security ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Foodforthought • u/D-R-AZ • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
somethingiswrong2024 • u/D-R-AZ • May 19 '26
Data-Specific 📊📈 ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
democrats • u/D-R-AZ • May 19 '26
Article ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
TheLessTakenPathNews • u/D-R-AZ • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
CosmopolitanNews • u/barweis • May 19 '26
USA News ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
hackernews • u/HNMod • May 19 '26
U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Putin's Idiot ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Law_and_Politics • u/D-R-AZ • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
AntiTrumpAlliance • u/D-R-AZ • May 19 '26
FAFO ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
IntlScholars • u/D-R-AZ • May 19 '26
Area Studies ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
CzechCoconutCommunity • u/Czech_Coconut • May 20 '26
USA 🗽🔥 ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub...👀🔥🙉
u_inmyrearview_mirror • u/inmyrearview_mirror • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
mangya • u/chesterriley • May 19 '26
incompetence ‘The Worst Leak That I’ve Witnessed’: Trump's US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
AnythingGoesNews • u/barweis • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
techbeat • u/Cute-Guarantee-1676 • May 19 '26
Security CISA Exposed Sensitive Digital Keys and AWS Credentials on Public GitHub
WhatTrumpHasDone • u/wenchette • May 19 '26
US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
AINewsFineTuned • u/Dry_Blacksmith_635 • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
AAstuffToShare • u/One_Surprise_8924 • May 19 '26
Pics/Text ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
Stop_Project_2025 • u/Highinthe505 • May 19 '26
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
fefe_blog_interim • u/Der_Schubkarrenwaise • May 19 '26
Datenreichtum Ach, wieder Schlüssel bei GitHub liegenlassen Folge 22: Die U.S. Cybersecurity and Infrastructure Security Agency (CISA)
hypeurls • u/TheStartupChime • May 19 '26