Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Scheduled Pinned Locked Moved Uncategorized
55 Posts 43 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    Link Preview Image
    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

    favicon

    (krebsonsecurity.com)

    snakeoilsalesman@mastodon.socialS This user is from outside of this forum
    snakeoilsalesman@mastodon.socialS This user is from outside of this forum
    snakeoilsalesman@mastodon.social
    wrote last edited by
    #46

    @briankrebs csv password docs... wow, just wow.

    1 Reply Last reply
    0
    • chux0r@infosec.exchangeC chux0r@infosec.exchange

      @briankrebs That sounds pretty bad, sure- but remember, whomever is left over there has the most important thing, which is loyalty.

      lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
      lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
      lawyersgunsnmoney@mstdn.social
      wrote last edited by
      #47

      @chux0r @briankrebs This is correct. The regime shitcanned everyone associated Biden’s CISA, including the contractors and brought their own people in. Watched it happen

      1 Reply Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        It's possible this set of instructions by the CISA contractor might have caused all the trouble:

        thetomas@social.toot9.deT This user is from outside of this forum
        thetomas@social.toot9.deT This user is from outside of this forum
        thetomas@social.toot9.de
        wrote last edited by
        #48

        @briankrebs Seems this dude doesn't know how git works and the organisation did not enforced Separation of work and private stuff (on different devices!).

        1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

          Link Preview Image
          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

          favicon

          (krebsonsecurity.com)

          hennichodernich@radiosocial.deH This user is from outside of this forum
          hennichodernich@radiosocial.deH This user is from outside of this forum
          hennichodernich@radiosocial.de
          wrote last edited by
          #49

          @briankrebs Worskpace

          1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

            Link Preview Image
            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

            favicon

            (krebsonsecurity.com)

            ppxl@social.tchncs.deP This user is from outside of this forum
            ppxl@social.tchncs.deP This user is from outside of this forum
            ppxl@social.tchncs.de
            wrote last edited by
            #50

            @briankrebs can't make this shit up 😳 anyway I am off for some gardening, enough of those pesky computers

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

              Link Preview Image
              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

              favicon

              (krebsonsecurity.com)

              grumpydad@infosec.exchangeG This user is from outside of this forum
              grumpydad@infosec.exchangeG This user is from outside of this forum
              grumpydad@infosec.exchange
              wrote last edited by
              #51

              @briankrebs There's no way this is not intentional.

              1 Reply Last reply
              0
              • legit_spaghetti@mastodo.neoliber.alL legit_spaghetti@mastodo.neoliber.al

                @briankrebs

                one of the most egregious government data leaks in recent history

                The word "recent" is doing a lot of heavy lifting here. Like, this is a colossal fuckup, but we've had a lot of other colossal fuckups recently, so... y'know, context.

                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.social
                wrote last edited by
                #52

                @Legit_Spaghetti @briankrebs "recent history" as in "this week".

                And it's only Tuesday, so...

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                  Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                  Link Preview Image
                  CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                  favicon

                  (krebsonsecurity.com)

                  okuna@social.tchncs.deO This user is from outside of this forum
                  okuna@social.tchncs.deO This user is from outside of this forum
                  okuna@social.tchncs.de
                  wrote last edited by
                  #53

                  @briankrebs make something idiot proof and nature will create a better idiot

                  Scnr

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                    Link Preview Image
                    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                    favicon

                    (krebsonsecurity.com)

                    airwhale@beige.partyA This user is from outside of this forum
                    airwhale@beige.partyA This user is from outside of this forum
                    airwhale@beige.party
                    wrote last edited by
                    #54

                    @briankrebs

                    So, does any of keys unlock the repo where the unredacted Epstein files are stored?

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                      ncrazed@fd00.spaceN This user is from outside of this forum
                      ncrazed@fd00.spaceN This user is from outside of this forum
                      ncrazed@fd00.space
                      wrote last edited by
                      #55

                      @briankrebs are these LLM instructions or a note to self kind of deal? 😬

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups