Secret CISA credentials found in public GitHub repo



Security researcher Brian Krebs brings us the news that America’s Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025.

The now-offline public repo—named, somewhat aspirationally, “Private-CISA”—was brought to Krebs’ attention by GitGuardian’s Guillaume Valadon, who was alerted to the repo’s presence by GitGuardian’s public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo’s owner.

In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator.

Testing by Seralys founder Philippe Caturegli showed that this was not a joke or hoax and that he was able to use the credentials in the Private-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level.”

Krebs notes that the repo appeared to be managed by Virginia-based Nightwing, a CISA contractor. Nightwing has so far not commented publicly, instead referring questions back to CISA.

This isn’t the first time CISA has screwed up—in fact, it’s not even the first time this year. In January, polygraph-failing acting CISA Director Madhu Gottumukkala uploaded sensitive government documents to ChatGPT after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel. Gottumukkala was removed from his role in February.



Source link

  • Related Posts

    Election Officials Are Getting Ready for ICE to Show Up at the Polls

    A week later, during the Conservative Political Action Conference meeting, now acting attorney general Todd Blanche endorsed the idea of ICE at the polls and repeated the conspiracy theory about…

    From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

    Shay Shwartz knows a lot about email phishing attacks. As a teenager, he made money as a hacker, but after getting caught at age 16, he realized he could use…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Election Officials Are Getting Ready for ICE to Show Up at the Polls

    Election Officials Are Getting Ready for ICE to Show Up at the Polls

    What’s Really In Your Mattress? I Toured 10 Mattress Factories To Find Out

    What’s Really In Your Mattress? I Toured 10 Mattress Factories To Find Out

    Canada Gazette – Part I, April 4, 2020, Vol. 154, No. 14

    Gold Steadies as Iran War Impasse Keeps Rate Hike Bets High

    Gold Steadies as Iran War Impasse Keeps Rate Hike Bets High

    Why Browns are giving Deshaun Watson another chance to be QB1

    Why Browns are giving Deshaun Watson another chance to be QB1

    There could be 1,000 or more victims of black-cab rapist John Worboys, says Carrie Johnson | John Worboys

    There could be 1,000 or more victims of black-cab rapist John Worboys, says Carrie Johnson | John Worboys