‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form, for some unknown amount of time, according to a report from Krebs on Security. The problem finally got fixed over the weekend, the report says.

Surely the secret information was buried in some obscure folder with an inscrutable name, I hear you saying. The repository was reportedly named “Private-CISA.”

But there’s no way the contents were that sensitive, you object. But the contents included passwords, keys, and tokens—and the passwords were plain text in a .CSV file.

CISA gave a statement to Krebs, saying the following:

“Currently, there is no indication that any sensitive data was compromised as a result of this incident[…] While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

Since the repository was created in November of last year, the duration of the vulnerability seems to have been about six months—but it could have been much shorter depending on what information as added when.

To refresh your memory, CISA is a relatively new branch of the Department of Homeland Security that has had an overall rough time during Trump 2.0, even though, by signing it into law in 2018, Trump actually midwifed CISA into existence during Administration 1.0, and sorry about the tangent, but Trump’s speech to mark the occasion was an exceptional example of Trump poetry, including excerpts like this one:

“The cyber battlespace evolves — and it is evolving, and unfortunately, faster than a lot of people want to talk about. But battlespace it is. So as the cyber battlespace evolves, this new agency will ensure that we confront the full range of threats from nation-states, cyber criminals, and other malicious actors, of which there are many.” 

Incontestably true, Mister President. Battlespace it is.

Anyway, Trump was enraged by information provided by CISA leadership during the period between the 2020 election and January 6, 2021 when he was on a mission to have the election results overturned in his favor. He fired the CISA director he appointed, and since taking office again, his CISA has been a chaotic farce. Neither of the acting directors he’s appointed so far have been confirmed by the Senate, and Trump has recently sought to drastically cut CISAs funding.

Now, to add to CISA’s worries, it seems, according to one interpretation from the Krebs report on what was in the repository, an individual employee working for a government contractor called Nightwing was using Github to move material from a work device to a home device—sorta like emailing documents to yourself, but somehow even less secure than that.

I’m no expert on federal Cybersecurity, but this from Krebs sounds like stuff we as citizens don’t want our government leaking:

“One of the exposed files, titled ‘importantAWStokens,’ included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — ‘AWS-Workspace-Firefox-Passwords.csv’ — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those system[s] included one called ‘LZ-DSO,’ which appears short for ‘Landing Zone DevSecOps,’ the agency’s secure code development environment.”

Kreb’s source about the information left out in the open was Guillaume Valadon of GitGuardian, a company that scans GitHub for secrets, meaning his business is finding situations like this one. Valadon told Krebs it was “the worst leak that I’ve witnessed in my career.”

Mike Pearl
Read More

Latest

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

Newsletter

Don't miss

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

New members for Registration Board | Local Business | trinidadexpress.com

THE Government has appointed new members to the Registration, Recognition and Certification Board (RRCB). The appointments were formalised during a ceremony hosted by the Ministry of Labour on April 10 at the ministry’s head office, International Waterfront Centre, Port of Spain. In a release from the ministry, Labour Minister Leroy Baptiste said the RRCB plays

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...