Secret CISA credentials found in public GitHub repo

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

CISA, the US cybersecurity agency, had plaintext passwords, SSH private keys, and tokens exposed in a public GitHub repository named 'Private-CISA' since at least November 2025. The repo was managed by CISA contractor Nightwing and had GitHub's default secret-protection features deliberately disabled. Security researcher Philippe Caturegli confirmed the credentials were valid and allowed high-privilege access to multiple AWS GovCloud accounts. The incident was discovered by GitGuardian's Guillaume Valadon via automated public code scanning. This follows a separate January incident where acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT, leading to his removal in February.

2m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoHow Lighting Design In The Callisto Protocol Elevates The Horror

Sort: