Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Lessons Learned from CISA's Recent GitHub Leak - News Directory 3

Lessons Learned from CISA’s Recent GitHub Leak

July 22, 2026 Lisa Park Tech
News Context
At a glance
  • The Cybersecurity and Infrastructure Security Agency (CISA) exposed administrative AWS GovCloud keys and plaintext passwords for dozens of internal systems in a public GitHub repository for nearly six...
  • The exposure stemmed from a contractor who published a repository titled Private CISA.
  • CISA confirmed in its analysis that the agency took more than 48 hours to invalidate the AWS keys and other secrets after the initial alert.
Original source: krebsonsecurity.com

The Cybersecurity and Infrastructure Security Agency (CISA) exposed administrative AWS GovCloud keys and plaintext passwords for dozens of internal systems in a public GitHub repository for nearly six months, according to a postmortem report from the agency. The leak, which included 844 MB of sensitive data, was finally addressed after notification from KrebsOnSecurity on May 15, 2026.

The exposure stemmed from a contractor who published a repository titled Private CISA. The leaked data included a file named importantAWStokens containing administrative credentials for three Amazon AWS GovCloud servers and a CSV file titled AWS-Workspace-Firefox-Passwords.csv, which listed internal system usernames and passwords in plaintext, according to reports from KrebsOnSecurity.

CISA confirmed in its analysis that the agency took more than 48 hours to invalidate the AWS keys and other secrets after the initial alert. Preston Werntz, acting chief information officer, and Brad Libbey, acting chief information security officer at CISA, attributed the delay to the complexity of the agency’s systems and its interconnections with industry and federal partners.

CISA Reporting Gaps and Response Failures

The agency admitted that its reporting channels for external security notifications were poorly defined. This lack of clarity forced the researcher who discovered the leak to attempt multiple contact methods, including emailing the contractor and using CISA’s vulnerability disclosure platform, which is designed for broader community vulnerabilities rather than internal agency leaks, according to the report by Werntz and Libbey.

Guillaume Valadon, a researcher at GitGuardian, stated that CISA ignored nine automated alerts regarding the exposed credentials before the May 15 notification. GitGuardian continuously scans public repositories for secrets and automatically alerts the affected accounts.

CISA GitHub Leak Lessons and the FSB Router Threat [Prime Cyber Insights]

Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure. Make it trivial to report a leak about you, not just about your products. The person reporting a leak to you is not the threat. Publish a security.txt, but do not stop there. Put reporting instructions in several prominent places, and make sure a report about your own infrastructure does not land in a product-bug queue.

Guillaume Valadon, GitGuardian researcher

In response, CISA stated it is refining its reporting channels to make them faster and more accessible for researchers. The agency suggested that organizations should publish reporting instructions in multiple prominent locations rather than relying solely on a security.txt file.

Technical Failures in Secret Management

The CISA postmortem revealed that the agency’s existing cybersecurity incident playbook did not include procedures for handling leaks on GitHub or other cloud services. This gap contributed to the six-month window during which the Private CISA repository remained public.

Valadon noted that while CISA’s report validates the need for continuous scanning, the agency’s failure to catch the plaintext passwords and backups internally suggests a lack of comprehensive internal scanning before the data left the building.

To remedy these vulnerabilities, CISA reported that it has since rotated all secrets and developed an action plan to improve the monitoring and management of developer secrets.

Mitigating Factors and Zero Trust Impact

Despite the exposure, CISA claimed that the impact was limited due to the agency’s adoption of zero-trust principles and enhanced logging capabilities in both production and development environments. According to the agency, these logs provided evidence that no mission or customer data was exposed and that the leaked credentials were not used outside of CISA’s own environments.

CISA also confirmed that the contractor responsible for the exposure had their system access revoked.

Valadon praised the agency’s transparency in the postmortem, stating that it is the first time a national cybersecurity agency has publicly advocated for the simplification of relations with security researchers and the use of secrets scanning.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Worth a look

  • Sony’s Shift Toward Digital Gaming and the Decline of Physical Discs
  • Norway’s Largest Independent Media Outlet Sells to Corporate Entity

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com