CISA's Own GitHub Leak Exposed AWS Keys for Six Months — Here's What Went Wrong
The Cybersecurity and Infrastructure Security Agency has published a postmortem examining how a third-party contractor managed to expose dozens of sensitive credentials — including keys to CISA's AWS Govcloud environment — in a publicly accessible GitHub repository. The leak sat unnoticed for close to six months, only coming to light after security journalist Brian Krebs flagged it to the agency.
The incident is notable not just because it happened to the very agency tasked with helping the rest of the federal government avoid exactly this kind of mistake, but because of what the after-action review reveals about CISA's own detection and response gaps. Reports indicate the agency lacked adequate automated scanning to catch credentials leaking into public code repositories, and its internal escalation process was slow even after the exposure was reported.
CISA says it has since tightened contractor oversight and improved its secret-scanning capabilities, but the episode has drawn attention from security researchers who argue the breakdown was entirely preventable using tools and practices that are now considered standard.