Skip to main content
See every side of every news story
Published loading...Updated

Secret CISA Credentials Found in Public GitHub Repo

Researchers said the archive held credentials for three AWS GovCloud servers and dozens of internal CISA systems, while CISA said no sensitive data was compromised.

  • On Friday, May 15, 2026, a public GitHub repository maintained by Nightwing, a government contractor, exposed 844 MB of sensitive U.S. Cybersecurity and Infrastructure Security Agency credentials before being taken offline.
  • Created in November 2025, the "Private-CISA" repository contained plaintext passwords and an explicit "how-to guide for disabling GitHub's secret scanning," which GitGuardian researcher Guillaume Valadon called a "catalogue of unsafe practices."
  • Exposed files included administrative access to AWS GovCloud and internal systems like "LZ-DSO," the agency's secure code development environment, which security consultant Philippe Caturegli confirmed could allow attackers a "persistent foothold."
  • CISA is investigating but claims "there is no indication that any sensitive data was compromised," while the agency has operated without a permanent director since January 20, 2025, following Jen Easterly's departure.
  • The incident exposes systemic vulnerabilities as CISA faces deep budget cuts and reduced staffing while maintaining responsibility for protecting national digital infrastructure from cyber threats.
Insights by Ground AI
Podcasts & Opinions

16 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

krebsonsecurity.com broke the news on Monday, May 18, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal