Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CISA Admin Leaked AWS GovCloud Keys on Github

0
High
Vulnerability
Published: Mon May 18 2026 (05/18/2026, 20:48:21 UTC)
Source: Krebs on Security

Description

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) publicly exposed highly privileged AWS GovCloud credentials and numerous internal system passwords in a GitHub repository named 'Private-CISA. ' The repository contained plaintext passwords, tokens, logs, and files detailing internal CISA software build and deployment processes. The exposed AWS keys remained valid for 48 hours after the repository was taken offline. CISA is investigating the incident and has stated there is currently no indication of sensitive data compromise. The leak highlights poor security practices by the contractor, including disabling GitHub's secret scanning features and using easily guessable passwords.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 19:41:33 UTC

Technical Analysis

A contractor for CISA maintained a public GitHub repository that exposed administrative credentials for multiple AWS GovCloud accounts and plaintext passwords for dozens of internal CISA systems. The repository also contained sensitive files related to CISA's software development and deployment processes. The exposure was discovered by a security researcher who alerted CISA. The AWS keys were confirmed valid and granted high privilege access. The repository was used as a synchronization workspace by the contractor, who disabled GitHub's default secret detection. CISA has acknowledged the incident and is investigating, with no confirmed data compromise at this time.

Potential Impact

The exposure of highly privileged AWS GovCloud credentials and internal system passwords could have allowed unauthorized access to critical CISA infrastructure and internal systems. The leak of software build and deployment details increases the risk of persistent backdoors or lateral movement within CISA networks if exploited. Although CISA reports no current indication of compromise, the incident represents a significant operational security failure and could have led to severe consequences if exploited by threat actors.

Mitigation Recommendations

CISA has taken the exposed GitHub repository offline and is investigating the incident. The exposed AWS keys remained valid for 48 hours after the repository was removed, indicating a need for immediate key revocation and credential rotation. Organizations should ensure that secret scanning features are enabled on code repositories and enforce strict credential management policies. CISA is implementing additional safeguards to prevent future occurrences. Patch status is not applicable as this is a credential exposure incident rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/","fetched":true,"fetchedAt":"2026-05-26T19:40:54.029Z","wordCount":1656}

Threat ID: 6a15f7466b9ae66727f4dbc5

Added to database: 5/26/2026, 7:40:54 PM

Last enriched: 5/26/2026, 7:41:33 PM

Last updated: 5/26/2026, 9:53:38 PM

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses