Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Trump Authorizes Private Firms for Cyber Operations Against Foreign Criminals
August 13, 2026
Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)
August 13, 2026
Cisco ASA, FTD Critical 0-Day Lets Attackers Trigger DoS
August 13, 2026
Home/CyberSecurity News/CISA Administrator Exposed AWS GovCloud Credentials on Public GitHub
CyberSecurity News

CISA Administrator Exposed AWS GovCloud Credentials on Public GitHub

Key Takeaways Highly sensitive U.S. government cloud credentials, including AWS GovCloud access keys and plaintext passwords, were publicly exposed on GitHub. The exposure originated from a...

Jennifer sherman
Jennifer sherman
May 19, 2026 4 Min Read
65 0

Key Takeaways

  • Highly sensitive U.S. government cloud credentials, including AWS GovCloud access keys and plaintext passwords, were publicly exposed on GitHub.
  • The exposure originated from a contractor working with CISA, who inadvertently published the data in a public repository named “Private-CISA.”
  • The exposed data included administrative credentials for multiple AWS GovCloud environments and access to CISA’s internal systems, posing a significant supply chain risk.
  • The repository was taken down, but some credentials remained valid for nearly 48 hours post-disclosure, and CISA is investigating with no evidence of active exploitation found yet.

CISA Contractor Exposes Critical AWS GovCloud Credentials on Public GitHub

In a significant cybersecurity incident, a contractor affiliated with the Cybersecurity and Infrastructure Security Agency (CISA) inadvertently uploaded highly sensitive U.S. government cloud credentials and other proprietary data to a public GitHub repository. This lapse has potentially exposed critical infrastructure details and internal system access.

Table Of Content

  • Key Takeaways
  • CISA Contractor Exposes Critical AWS GovCloud Credentials on Public GitHub
  • Discovery and Initial Response
  • Details of the Exposed Data
  • Contractor Link and CISA’s Response
  • What You Should Do

The repository, titled “Private-CISA,” contained a trove of confidential information, including AWS GovCloud credentials, unencrypted passwords, API tokens, and various internal system specifics. It remained accessible to the public until mid-May 2026, raising serious concerns among security experts.

Industry researchers are categorizing this event as one of the most severe government-related data exposures observed in recent years, highlighting the profound implications of such a breach.

Discovery and Initial Response

The exposure was initially detected by Guillaume Valadon, a researcher at GitGuardian, a firm specializing in scanning public repositories for leaked secrets. Valadon described the information within the repository as “extremely sensitive” and reported initial difficulties in alerting the owner about the vulnerability.

Following the initial discovery, the findings were escalated and subsequently shared with KrebsOnSecurity, which prompted a deeper investigation into the extent of the exposure.

Details of the Exposed Data

Analysis of the “Private-CISA” repository confirmed that it contained administrative credentials for at least three distinct AWS GovCloud environments. These environments are specifically designed to host and manage sensitive U.S. government workloads, underscoring the gravity of the exposure.

Further examination revealed a file named “AWS-Workspace-Firefox-Passwords.csv,” which contained dozens of plaintext usernames and passwords. These credentials were linked to various internal CISA systems, including a DevSecOps environment identified as “LZ-DSO.”

Philippe Caturegli, founder of the security consultancy Seralys, independently verified that some of the exposed AWS credentials remained active and provided high-level access at the time of their discovery. Caturegli also noted the presence of credentials for CISA’s internal “artifactory,” a central system used for managing and distributing software components. Compromise of such a system could enable threat actors to inject malicious code into software pipelines, potentially affecting numerous systems during deployment.

Researchers also pointed to significant security deficiencies within the repository. Sensitive data was stored without encryption, and crucially, GitHub’s native secret scanning protections had been intentionally disabled. Commit logs suggest the repository may have been used more as a personal file synchronization tool or a temporary workspace rather than a securely managed development project.

“The patterns indicate this was likely used to sync files between different machines, possibly a work and home environment,” Caturegli explained, adding that such usage “doesn’t reduce the severity it actually makes it worse.”

Contractor Link and CISA’s Response

Reports indicated that the exposed repository was associated with a contractor from Nightwing, a U.S.-based government services firm. The contractor’s GitHub account had been active since 2018, with the “Private-CISA” repository itself being created in November 2025.

Although the repository was promptly removed following public disclosure, the exposed AWS credentials reportedly remained valid for nearly 48 hours afterward, extending the window of potential risk.

CISA has acknowledged the incident and initiated an active investigation. The agency stated that, as of now, there is no evidence suggesting active exploitation of the exposed credentials. However, CISA emphasized that additional security measures are being implemented to mitigate any potential future risks.

This incident occurs amid reports of significant workforce reductions at CISA, attributed to budget cuts and restructuring. Security experts caution that such operational pressures can elevate the risk of human error and security misconfigurations.

The overall event serves as a stark reminder that even organizations at the forefront of national cybersecurity must maintain rigorous security practices, particularly concerning credential management and secure development workflows, to prevent basic errors from leading to critical compromises.

What You Should Do

  • Implement Automated Secret Scanning: Ensure all code repositories, especially those handling sensitive data, are continuously scanned for exposed credentials and secrets using automated tools.
  • Enforce Strong Access Controls: Regularly audit and enforce least privilege principles for all cloud and internal system access.
  • Mandate Multi-Factor Authentication (MFA): Require MFA for all accounts, especially those with administrative privileges, to add an extra layer of security.
  • Conduct Regular Security Training: Educate contractors and employees on secure coding practices, data handling, and the dangers of exposing sensitive information in public repositories.
  • Rotate Credentials Frequently: Implement a policy for regular rotation of API keys, passwords, and other credentials, especially after any suspected exposure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Microsoft Entra ID Flaw Exposes Microsoft 365, Azure Data

Next Post

Critical Vulnerabilities Found in @antv Packages After npm Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
China-linked Hackers Use AI Agents to Attack Taiwan Government Websites
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us