Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    June 16, 2026

    Trump meets Ukraine’s Zelenskyy as Iran moves into ‘rear-view mirror’

    June 16, 2026

    Stocks making the biggest moves premarket: SPCX, HOOD, HUN

    June 16, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»Secret CISA credentials found in public GitHub repo
    Tech

    Secret CISA credentials found in public GitHub repo

    franperez66q@protonmail.comBy franperez66q@protonmail.comMay 20, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.

    The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.

    In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.

    Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”

    Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.

    This isn’t the first time CISA has screwed up—in fact, it’s not even the first time this year. In January, polygraph-failing acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel. Gottumukkala was removed from his role in February.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    June 16, 2026

    Commodore’s newest gadget is a flip phone that blocks social media and browsers

    June 16, 2026

    Who is Gwynne Shotwell, Elon Musk’s second-in-command at SpaceX?

    June 16, 2026

    SpaceX gains 9% in premarket trading as momentum builds

    June 16, 2026

    Qualcomm working on 40 new AI device designs

    June 16, 2026

    Good news—we have extra time before the Sun ends life on Earth

    June 16, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    June 16, 2026

    Trump meets Ukraine’s Zelenskyy as Iran moves into ‘rear-view mirror’

    June 16, 2026

    Stocks making the biggest moves premarket: SPCX, HOOD, HUN

    June 16, 2026

    Meta’s Threads reaches 500 million monthly users

    June 16, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.