CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 136

As cited

Copy frozen at (site build).

breaches incidents

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

A CISA contractor intentionally published AWS GovCloud credentials and internal secrets on a public GitHub account in May 2025, exposing plaintext credentials to dozens of agency systems. Congressional lawmakers are demanding answers about the security lapse, as CISA struggles to invalidate the leaked credentials more than a week after GitGuardian first notified the agency. CISA claims no sensitive data was compromised, but security experts note the exposure provided adversaries with information and access pathways to federal networks.

Why it matters: Federal agencies and contractors relying on CISA for cybersecurity guidance face heightened risk if the agency cannot demonstrate secure credential management and incident response; practitioners should review their own code repositories and secret management practices immediately, and assess whether CISA-provided security frameworks have been compromised by the exposure of internal systems and CI/CD pipeline access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

A CISA contractor intentionally published AWS GovCloud credentials and internal secrets on a public GitHub account in May 2025, exposing plaintext credentials to dozens of agency systems. Congressional lawmakers are demanding answers about the security lapse, as CISA struggles to invalidate the leaked credentials more than a week after GitGuardian first notified the agency. CISA claims no sensitive data was compromised, but security experts note the exposure provided adversaries with information and access pathways to federal networks.

Why it matters: Federal agencies and contractors relying on CISA for cybersecurity guidance face heightened risk if the agency cannot demonstrate secure credential management and incident response; practitioners should review their own code repositories and secret management practices immediately, and assess whether CISA-provided security frameworks have been compromised by the exposure of internal systems and CI/CD pipeline access.

VendorsAmazon Web ServicesGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary