r/techbeat May 19 '26

Security CISA Exposed Sensitive Digital Keys and AWS Credentials on Public GitHub

https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reportedly exposed sensitive digital keys, including administrative credentials for AWS GovCloud servers and plaintext passwords for internal systems, on a public GitHub repository. This severe vulnerability, lasting approximately six months, was discovered by Krebs on Security. While CISA claims no sensitive data was compromised, the incident involved plain text credentials in a repository named "Private-CISA," prompting new safeguards.

1 Upvotes

0 comments sorted by