September 25, 2026
September 25, 2026
A CISA contractor accidentally left an 844 MB public GitHub repository containing sensitive agency information exposed for nearly six months. The files included administrative credentials for three AWS GovCloud servers and plaintext usernames and passwords for numerous internal systems. GitGuardian discovered the repository and attempted to notify CISA, but nine automated warnings reportedly went unanswered before the company contacted KrebsOnSecurity. Although CISA acknowledged the eventual alert quickly, it required more than 48 hours to invalidate many of the exposed secrets, citing the complexity of interconnected systems involving federal and industry partners.
CISA’s postmortem highlights several broadly applicable lessons: organizations need continuously operating secret-scanning tools, mature and regularly tested credential-rotation procedures, and incident-response playbooks that explicitly cover GitHub and other cloud services. They should also provide clear, prominent channels for researchers to report compromises affecting the organization itself, rather than routing such warnings through product-vulnerability systems. CISA said enhanced logging and zero-trust controls helped establish that the leaked credentials were not used externally and that no customer or mission data was exposed. The agency revoked the contractor’s access, rotated the secrets and began improving developer-secret management and monitoring, while its unusually transparent account was praised as a useful model for post-incident disclosure.
Source: KrebsOnSecurity