| |
CISA Admin Leaked AWS GovCloud Keys on GitHub
A CISA contractor publicly exposed highly sensitive AWS GovCloud credentials, plaintext passwords, and internal system files on GitHub until this past weekend, representing one of the most significant government data leaks in recent history. The exposed materials included administrative keys to three AWS GovCloud servers, passwords to dozens of internal CISA systems, and access to the agency's code repository, which security researchers say could allow attackers to inject backdoors into CISA's software builds. The leak resulted from poor security practices, including disabling GitHub's automatic secrets detection feature and using the repository as a personal working directory rather than a curated project.
Read Full Article →
← More Tech news