General Discussion
Related: Editorials & Other Articles, Issue Forums, Alliance Forums, Region ForumsCISA exposes files representing an egregious government data leak. Big oops.
Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
ð¨ Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
— Reset America (@reset-america.bsky.social) 2026-05-19T13:24:08.419Z
LearnedHand
(5,629 posts)I honestly dont understand this. Government IT environments typically dont let you choose your own passwords ESPECIALLY for priveliged access and they enforce random, complex passwords that are forced to change frequently. In addition, they typically require a hardware-based access key or token. And CISA is the federal agency charged with ensuring government systems are secure????
Kid Berwyn
(25,164 posts)Passwords were stored as plain text in a public GitHub repository.
by Mike Pearl
Gizmodo, May 18, 2026,
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form, for some unknown amount of time, according to a report from Krebs on Security. The problem finally got fixed over the weekend, the report says.
Surely the secret information was buried in some obscure folder with an inscrutable name, I hear you saying. The repository was reportedly named Private-CISA.
But theres no way the contents were that sensitive, you object. But the contents included passwords, keys, and tokensand the passwords were plain text in a .CSV file.
CISA gave a statement to Krebs, saying the following:
Currently, there is no indication that any sensitive data was compromised as a result of this incident[ ] While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.
Since the repository was created in November of last year, the duration of the vulnerability seems to have been about six monthsbut it could have been much shorter depending on what information as added when.
Continues...
https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330
Thanks, Putin.
This event is being excoriated in cyber security channels today.
Heres a more technical article
CISA Admin Leaked AWS GovCloud Keys on Github
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/#more-73607
Since January 2025 CISA has not had a Director (only Acting Director) and DOGE slahed its funding and they lost 30% of their workforce. Gee what could go wrong??