| |
# Summary The U.S. Cybersecurity and Infrastructure Security Agency (CISA) left sensitive credentials—including passwords in plain text, AWS administrative keys, and tokens—publicly exposed on GitHub in a repository named "Private-CISA" for approximately six months before fixing the issue over a recent weekend. The exposed files contained access credentials to cloud storage accounts and internal CISA systems, though the agency claims there is no evidence the data was compromised. A GitGuardian security researcher called it "the worst leak" he has witnessed in his career.
Read Full Article →
← More Tech news