GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

CISA's Own GitHub Leak Exposed AWS Keys for Six Months — Here's What Went Wrong

A contractor's public repository quietly leaked internal CISA credentials, including AWS Govcloud keys, for nearly half a year before anyone at the agency noticed.

The Cybersecurity and Infrastructure Security Agency has published a postmortem examining how a third-party contractor managed to expose dozens of sensitive credentials — including keys to CISA's AWS Govcloud environment — in a publicly accessible GitHub repository. The leak sat unnoticed for close to six months, only coming to light after security journalist Brian Krebs flagged it to the agency.

The incident is notable not just because it happened to the very agency tasked with helping the rest of the federal government avoid exactly this kind of mistake, but because of what the after-action review reveals about CISA's own detection and response gaps. Reports indicate the agency lacked adequate automated scanning to catch credentials leaking into public code repositories, and its internal escalation process was slow even after the exposure was reported.

CISA says it has since tightened contractor oversight and improved its secret-scanning capabilities, but the episode has drawn attention from security researchers who argue the breakdown was entirely preventable using tools and practices that are now considered standard.

Why it matters: This wasn't a novel attack technique — it was a basic secrets-management failure of the kind automated scanners like GitGuardian or GitHub's own secret scanning are built to catch. If the agency that issues cybersecurity guidance to the rest of government can miss a public credential leak for six months, it's a strong signal that every org, especially those relying on contractors, should audit whether their own repo-scanning and vendor-access controls would actually catch this in real time.

Sources: Krebs on Security