Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Uncategorized
  • Krebs On Security
  • Lessons Learned from CISA’s Recent GitHub Leak
  • Krebs On Security

Lessons Learned from CISA’s Recent GitHub Leak

BrianKrebs Published: July 13, 2026 | Updated: August 31, 2026 4 min read
0 views

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.

CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak, CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take longer than anticipated.

“Drawing on this experience, CISA encourages others to maintain mature and well-tested key management capabilities,” the report notes.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties. The postmortem stresses that clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers.

“In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues – including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter,” reads the analysis written by Preston Werntz and Brad Libbey, the acting chief information officer and acting chief information security officer at CISA, respectively.

CISA said it is refining its reporting channels to make them easier and faster for researchers. “Additionally, while many researchers rely on the security.txt file, organizations can ensure clarity by publishing reporting instructions in multiple prominent locations,” the CISA authors wrote.

Guillaume Valadon, the GitGuardian researcher who first contacted KrebsOnSecurity about the exposed CISA credentials, said CISA ignored nine automated alerts about the exposed credentials prior to our notification on May 15. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

“Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure,” Valadon wrote in an analysis of CISA’s report. “Make it trivial to report a leak about you, not just about your products. The person reporting a leak to you is not the threat. Publish a security.txt, but do not stop there. Put reporting instructions in several prominent places, and make sure a report about your own infrastructure does not land in a product-bug queue.”

The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.

The report notes that while CISA had developed a playbook for responding to cybersecurity incidents, that playbook somehow didn’t include what to do in situations involving GitHub or other cloud services. Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“The Private-CISA repository sat public for six months,” Valadon wrote. “Continuous monitoring of public GitHub surfaced it. Comprehensive internal scanning could have caught the plaintext passwords and committed backups long before they left the building.”

CISA gave itself passing grades on several areas of security preparedness that it said helped the agency gauge the scope and impact of the exposed secrets, including enhanced logging capabilities, and the adoption of zero-trust principles in both its production and development systems. CISA said those detailed logs allowed it to show that no customer or mission data was exposed, and that the leaked credentials were not used outside of CISA’s environments. The agency said the contractor who exposed the secrets had their system access revoked.

Valadon reckons the biggest takeaway is the CISA postmortem itself, and praised the agency for being transparent about what worked and what didn’t.

“To my knowledge, it is also the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers,” Valadon wrote. “That is exactly the incident communication we should expect from every organization.”

About The Author

BrianKrebs

See author's posts

Original post here

What do you feel about this?

  • Krebs On Security

Post navigation

Previous: Felons, Fraudsters Flog Offensive Cybersecurity Startup
Next: Microsoft Patches a Record 570 Security Flaws

Author's Other Posts

FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

August 31, 2026 0 0
Who’s Tracking You? Use This New Service to Find Out decryptads-ESPN.png

Who’s Tracking You? Use This New Service to Find Out

August 31, 2026 0 0
Microsoft Plugs Nearly 400 Security Holes workingonpc.png

Microsoft Plugs Nearly 400 Security Holes

August 31, 2026 0 0

Related Stories

nexus-phegseth.png
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

BrianKrebs September 1, 2026 0 0
  • Krebs On Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

BrianKrebs August 31, 2026 0 0
decryptads-ESPN.png
  • Krebs On Security

Who’s Tracking You? Use This New Service to Find Out

BrianKrebs August 31, 2026 0 0
workingonpc.png
  • Krebs On Security

Microsoft Plugs Nearly 400 Security Holes

BrianKrebs August 31, 2026 0 0
moucka-surveillance.png
  • Krebs On Security

Canadian Man Pleads Guilty in Snowflake Extortions

BrianKrebs August 31, 2026 0 0
h96-amazon.png
  • Krebs On Security

Read This Before You Buy That TV Streaming Stick

BrianKrebs August 31, 2026 0 0

Trending Now

FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png 1

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure jfrog.jpg 2

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

September 1, 2026 0 0
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems brazil.jpg 3

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

September 1, 2026 0 0
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds iphone.jpg 4

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

September 1, 2026 0 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png 1
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure jfrog.jpg 2
  • The Hacker News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

September 1, 2026 0 0
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems brazil.jpg 3
  • The Hacker News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

September 1, 2026 0 0
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds iphone.jpg 4
  • The Hacker News

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

September 1, 2026 0 0
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests iran-hacking.jpg 5
  • The Hacker News

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

September 1, 2026 0 0
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones click.jpg 6
  • The Hacker News

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

September 1, 2026 0 0
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 metr.jpg 7
  • The Hacker News

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

September 1, 2026 0 0

You may have missed

nexus-phegseth.png
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

BrianKrebs September 1, 2026 0 0
jfrog.jpg
  • The Hacker News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

[email protected] The Hacker News September 1, 2026 0 0
brazil.jpg
  • The Hacker News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

[email protected] The Hacker News September 1, 2026 0 0
iphone.jpg
  • The Hacker News

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

[email protected] The Hacker News September 1, 2026 0 0
Copyright © 2026 All rights reserved. | MoreNews by AF themes.