The Cybersecurity and Infrastructure Security Agency exposed highly privileged AWS GovCloud credentials and plaintext passwords for dozens of internal systems on a public GitHub repository for at least six months, from November 13, 2025 until May 2026. A Nightwing contractor maintained the repository named 'Private-CISA' and had deliberately disabled GitHub's secret scanning feature, apparently using it to synchronize work between computers. The repository contained files like 'importantAWStokens' granting administrative access to three AWS GovCloud environments and 'AWS-Workspace-Firefox-Passwords.csv' with plaintext credentials for internal CISA systems. Security researchers Guillaume Valadon of GitGuardian and Philippe Caturegli of Seralys discovered and validated the exposure, with some AWS keys remaining valid up to 48 hours after takedown. CISA has revoked the credentials and is investigating, though it has not disclosed whether unauthorized access occurred, while the agency has lost nearly a third of its workforce since the start of the second Trump administration.
Aug 10, 2026 · 3 sources
Aug 10, 2026 · 8 sources
Aug 9, 2026 · 9 sources
Aug 8, 2026 · 2 sources
Story comments
Loading comments…