CISA Admin Leaked AWS GovCloud Keys On Github (krebsonsecurity.com) 40
An anonymous reader quotes a report from KrebsOnSecurity: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon's company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn't responding and the information exposed was highly sensitive.
The GitHub repository that Valadon flagged was named "Private-CISA," and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets. Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories. "Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature," Valadon wrote in an email. "I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I've witnessed in my career. It is obviously an individual's mistake, but I believe that it might reveal internal practices." "Currently, there is no indication that any sensitive data was compromised as a result of this incident," a CISA spokesperson wrote. "While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences."
The GitHub account in question was taken offline shortly after CISA was notified about the exposure. However, according to Caturegli, the exposed AWS keys remained valid for another 48 hours.
"What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025," Caturegli said. "This would be an embarrassing leak for any company, but it's even more so in this case because it's CISA."
The GitHub repository that Valadon flagged was named "Private-CISA," and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets. Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories. "Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature," Valadon wrote in an email. "I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I've witnessed in my career. It is obviously an individual's mistake, but I believe that it might reveal internal practices." "Currently, there is no indication that any sensitive data was compromised as a result of this incident," a CISA spokesperson wrote. "While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences."
The GitHub account in question was taken offline shortly after CISA was notified about the exposure. However, according to Caturegli, the exposed AWS keys remained valid for another 48 hours.
"What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025," Caturegli said. "This would be an embarrassing leak for any company, but it's even more so in this case because it's CISA."
Seriously (Score:5, Funny)
How could Joe Biden allow this to happen?
Re: (Score:2)
How could Joe Biden allow this to happen?
Thankfully, Trump hires, "only the best people". /s
Re: (Score:1)
Who is the president now? Obama? Clinton? Biden? Carter?
I can't remember.
Feeding the AI is rarely Funny (Score:2)
Even though I don't even know what sort of humor I was hoping for on this story, I'm sure AC's brain fart was not it.
Just read another book with something about why anonymity encourages people to become worse people over time... Must have been in the Facebook-related stuff.
Me? I didn't even want to use GitHub but Claude.ai made me do it.
Re: (Score:3)
I'm honestly surprised that the CISA spokeswoman didn't include a non-sequitir like "we are re-building a world class workforce after the DEI-driven destruction caused by Biden's administration" nor a statement praising Donald Trump. Typically at least one of the two is included in any deflection offered by the current administraiton.
Interesting (Score:3, Insightful)
Almost like firing staff indiscriminately and hiring loyalists leads to fuck ups.
Re: (Score:3)
maybe partly, but the reality I know as someone who reads a lot of penetration testing reports, is big supposedly mature organizations end up putting useful credentials (as in not just some QA mock enviornment nobody cares about in CI/CD stuff) in their git commits, all the freaking time.
Cloud security is a s*** show a lot of places, even places with mostly capable people, it only takes one idiot or one careless person to really mess things up badly. That is the problem with PaaS/SaaS model generally.
Re: Interesting (Score:3)
What you say is true, but is compounded by the downsized high productivity consider humans as fungible capital/reaources development mentality of the last couple decades.
Re: (Score:1)
They will never learn that Ideological purity and competence are not the same thing.
After the OMB hack, this one is minor (Score:2)
Re: (Score:2)
> pay the Chinese to host our fucking military servers
no, but that's literally what they were doing.
DC doesn't run a serious country.
https://slashdot.org/story/25/... [slashdot.org]
Damn. Old news, I guess. (Score:2)
Re: (Score:2)
I agree with your sentiment 100%, but the hacked entity was OPM [wikipedia.org], not OMB.
Re:After the s/OMB/OPM/g hack, this one is minor (Score:2)
Re: After the OMB hack, this one is minor (Score:2)
Shameful (Score:3)
Welcome to modern cybersecurity. (Score:2)
Another disturbing point, why was GitHub being used? Standing up a Git server is ea
Re: Welcome to modern cybersecurity. (Score:1)
Re: (Score:2)
Own github repo needs backups and resilience against failing HDs etc. GitHub have these and it is less likely your repository is destroyed by crashes of hardware or software errors. GitHub also donâ€(TM)t cost very much.
Excellent point - IE: GitHub ALSO has a backup of all these credentials in their backups and mirrored across who knows how many places, all of which could still be leaked.
Sorry, but there's no way to sell this as a good decision.
Re: (Score:2)
Another disturbing point, why was GitHub being used? Standing up a Git server is easy
Yeah that. Why not a GitGov or GovHub? It makes zero sense.
Re: (Score:2)
Re: Welcome to modern cybersecurity. (Score:1)
Github was probably being used because someone in government considers it COTS software from a reliable American corporation. Those people who used to insist on using IIS instead of Apache are still around!
Re: (Score:2)
Deliberate (Score:1)
Please, there's no way this was by mistake. It's a hack from the inside. Just like all of the others.
Re: Deliberate (Score:2)
oh great fucking timing (Score:2)
I was just going to remind IS of their password policy recommendations that everyone doing business with the feds are supposed to follow.
So much for that fucking idea.
And this is why... (Score:5, Informative)
...we laugh when a Government says "We must have backdoor access to everyone's cryptography, it will be perfectly safe with us."
Has nothing to do with an administration! (Score:2)
They do not check the paperwork against the actual real work IT operations.
That is why they fail! Nothing is really being checked, except that the audit documentation says what it needs to say.
Re: (Score:2)
Did you post this using your new Trump phone?
Re: (Score:1)
Uh huh, so how many times did this happen during Biden or Obama?
"The now fired, previous head of ..." (Score:2)
Surely by now.