Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
U.S. Cybersecurity Agency CISA Exposed Sensitive AWS GovCloud Credentials in Public GitHub Repository
00

U.S. Cybersecurity Agency CISA Exposed Sensitive AWS GovCloud Credentials in Public GitHub Repository

May 20, 2026

The Cybersecurity and Infrastructure Security Agency exposed highly privileged AWS GovCloud credentials and plaintext passwords for dozens of internal systems on a public GitHub repository for at least six months, from November 13, 2025 until May 2026. A Nightwing contractor maintained the repository named 'Private-CISA' and had deliberately disabled GitHub's secret scanning feature, apparently using it to synchronize work between computers. The repository contained files like 'importantAWStokens' granting administrative access to three AWS GovCloud environments and 'AWS-Workspace-Firefox-Passwords.csv' with plaintext credentials for internal CISA systems. Security researchers Guillaume Valadon of GitGuardian and Philippe Caturegli of Seralys discovered and validated the exposure, with some AWS keys remaining valid up to 48 hours after takedown. CISA has revoked the credentials and is investigating, though it has not disclosed whether unauthorized access occurred, while the agency has lost nearly a third of its workforce since the start of the second Trump administration.

GitHub credential exposure

  • ▪The GitHub repository remained publicly accessible until it was taken offline over the weekend after researchers notified the Cybersecurity and Infrastructure Security Agency.
  • ▪The now-deleted GitHub repository named 'Private-CISA' was created on November 13, 2025, and remained active with regular commits until its removal.
  • ▪Some exposed AWS keys remained valid for up to 48 hours after the GitHub repository was taken down.

Scope of leaked materials

  • ▪Access to the Cybersecurity and Infrastructure Security Agency's Artifactory repository, which stores code packages used for software builds, was exposed in the GitHub leak.
  • ▪The GitHub repository contained plaintext passwords, cloud access tokens and detailed files showing how the Cybersecurity and Infrastructure Security Agency builds, tests and deploys internal software.
  • ▪The GitHub repository contained a file named 'AWS-Workspace-Firefox-Passwords.csv' that listed plaintext usernames and passwords for numerous internal Cybersecurity and Infrastructure Security Agency systems, including a secure development environment called 'LZ-DSO'.
  • ▪The GitHub repository contained a file named 'importantAWStokens' that granted high-level administrative access to at least three AWS GovCloud environments used by the Cybersecurity and Infrastructure Security Agency.

Security researcher discovery

  • ▪Philippe Caturegli of Seralys independently validated several of the exposed credentials.
  • ▪The article about the Cybersecurity and Infrastructure Security Agency GitHub credential exposure was published on May 20, 2026.
  • ▪Guillaume Valadon, a researcher with GitGuardian, first flagged the GitHub credential exposure.
  • ▪Guillaume Valadon attempted to contact the GitHub repository owner before reaching out to the Cybersecurity and Infrastructure Security Agency after receiving no response.

CISA investigation response

  • ▪The Cybersecurity and Infrastructure Security Agency confirmed it is investigating the GitHub credential exposure incident but said there is currently no indication that any sensitive data was compromised.
  • ▪The Cybersecurity and Infrastructure Security Agency has revoked the exposed credentials and is conducting a full audit of related systems.
  • ▪The Cybersecurity and Infrastructure Security Agency has not disclosed how long the GitHub repository was publicly accessible or whether any unauthorized access occurred before discovery.
  • ▪The Cybersecurity and Infrastructure Security Agency urged federal partners and critical infrastructure operators to review their own credential hygiene and GitHub security practices in light of the credential exposure.

Nightwing contractor failures

  • ▪The Nightwing contractor who maintained the GitHub repository had deliberately disabled GitHub's built-in secret scanning feature.
  • ▪The Nightwing contractor who maintained the GitHub repository appeared to use the public repository as a personal synchronization tool between work and home computers.
  • ▪The Nightwing contractor's GitHub account was created in 2018 and used both official Cybersecurity and Infrastructure Security Agency-associated emails and personal addresses.

Government cybersecurity practices

  • ▪The Cybersecurity and Infrastructure Security Agency has lost nearly a third of its workforce since the start of the second Trump administration due to early retirements, buyouts and resignations.

Perspective of Security researchers Guillaume Valadon and Philippe Caturegli

  • ▪Security experts described the Cybersecurity and Infrastructure Security Agency's GitHub credential leak as one of the worst credential leaks they have witnessed.

8 sources

Gizmodo
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
View source article
Techloy
CISA GitHub Data Leak: Sensitive Credentials, Passwords Posted to Public Repository
View source article
Usaherald
“Worst Leak I’ve Ever Seen”: U.S. Cyber Agency Accidentally Exposes Secret Access Keys on GitHub - USA Herald
View source article
Krebsonsecurity
CISA Admin Leaked AWS GovCloud Keys on Github
View source article
Gadgetreview
U.S. Cybersecurity Agency Just Left the Keys to the Kingdom on Public GitHub
View source article

Featured stories

View more in Credential management

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources

OpenAI sued over Hugging Face hack by AI safety nonprofit

Sep 30, 2026 · 2 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Story comments

Loading comments…

Related entities

Amazon Web Services GovCloudAWS GovCloudUnited StatesCybersecurity and Infrastructure Security AgencyGitHubCISA

Topics

Credential managementAI privacy & surveillanceAI securityCloud securityGovernment cybersecurity

Featured stories

View more in Credential management

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources

OpenAI sued over Hugging Face hack by AI safety nonprofit

Sep 30, 2026 · 2 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources