As cited
Copy frozen at (site build).
breaches incidents
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
A CISA contractor intentionally published AWS GovCloud credentials and internal secrets on a public GitHub account in May 2025, exposing plaintext credentials to dozens of agency systems. Congressional lawmakers are demanding answers about the security lapse, as CISA struggles to invalidate the leaked credentials more than a week after GitGuardian first notified the agency. CISA claims no sensitive data was compromised, but security experts note the exposure provided adversaries with information and access pathways to federal networks.
Why it matters: Federal agencies and contractors relying on CISA for cybersecurity guidance face heightened risk if the agency cannot demonstrate secure credential management and incident response; practitioners should review their own code repositories and secret management practices immediately, and assess whether CISA-provided security frameworks have been compromised by the exposure of internal systems and CI/CD pipeline access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
A CISA contractor intentionally published AWS GovCloud credentials and internal secrets on a public GitHub account in May 2025, exposing plaintext credentials to dozens of agency systems. Congressional lawmakers are demanding answers about the security lapse, as CISA struggles to invalidate the leaked credentials more than a week after GitGuardian first notified the agency. CISA claims no sensitive data was compromised, but security experts note the exposure provided adversaries with information and access pathways to federal networks.
Why it matters: Federal agencies and contractors relying on CISA for cybersecurity guidance face heightened risk if the agency cannot demonstrate secure credential management and incident response; practitioners should review their own code repositories and secret management practices immediately, and assess whether CISA-provided security frameworks have been compromised by the exposure of internal systems and CI/CD pipeline access.
- Source published
- First seen by Cybersecurity Tracker