GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

CISA's Own GitHub Leak Exposed AWS Keys for Six Months — Here's What Went Wrong

A contractor's public repository quietly leaked internal CISA credentials, including AWS Govcloud keys, for nearly half a year before anyone at the agency noticed.

The Cybersecurity and Infrastructure Security Agency has published a postmortem examining how a third-party contractor managed to expose dozens of sensitive credentials — including keys to CISA's AWS Govcloud environment — in a publicly accessible GitHub repository. The leak sat unnoticed for close to six months, only coming to light after security journalist Brian Krebs flagged it to the agency.

The incident is notable not just because it happened to the very agency tasked with helping the rest of the federal government avoid exactly this kind of mistake, but because of what the after-action review reveals about CISA's own detection and response gaps. Reports indicate the agency lacked adequate automated scanning to catch credentials leaking into public code repositories, and its internal escalation process was slow even after the exposure was reported.

CISA says it has since tightened contractor oversight and improved its secret-scanning capabilities, but the episode has drawn attention from security researchers who argue the breakdown was entirely preventable using tools and practices that are now considered standard.

Why it matters: This wasn't a novel attack technique — it was a basic secrets-management failure of the kind automated scanners like GitGuardian or GitHub's own secret scanning are built to catch. If the agency that issues cybersecurity guidance to the rest of government can miss a public credential leak for six months, it's a strong signal that every org, especially those relying on contractors, should audit whether their own repo-scanning and vendor-access controls would actually catch this in real time.

Sources: Krebs on Security