Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Record 230 people cross English Channel in one small boat

    August 10, 2026

    SpaceX stock rebounds to near $135 IPO price

    August 10, 2026

    Trump foreign licensing income surged to $59.5 million

    August 10, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»Secret CISA credentials found in public GitHub repo
    Tech

    Secret CISA credentials found in public GitHub repo

    franperez66q@protonmail.comBy franperez66q@protonmail.comMay 20, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.

    The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.

    In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.

    Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”

    Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.

    This isn’t the first time CISA has screwed up—in fact, it’s not even the first time this year. In January, polygraph-failing acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel. Gottumukkala was removed from his role in February.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    SpaceX stock rebounds to near $135 IPO price

    August 10, 2026

    Archer shares surge after Boeing stake, aircraft subsidiary deal

    August 10, 2026

    Peer review is overwhelmed—can it survive in the AI era?

    August 10, 2026

    TSMC sees 45% sales surge as AI demand stays strong

    August 10, 2026

    Israeli startup Irregular linked to AI hacks OpenAI, Anthropic, Meta

    August 10, 2026

    Mount Toba eruption doesn’t seem like it could nearly kill our species

    August 9, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Record 230 people cross English Channel in one small boat

    August 10, 2026

    SpaceX stock rebounds to near $135 IPO price

    August 10, 2026

    Trump foreign licensing income surged to $59.5 million

    August 10, 2026

    Archer shares surge after Boeing stake, aircraft subsidiary deal

    August 10, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.