Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Scheduled Pinned Locked Moved Uncategorized
55 Posts 43 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • elfin@mstdn.socialE elfin@mstdn.social

    @briankrebs I'm out of popcorn ... but there's a theater a few blocks away! Back in a sec to read this.

    elfin@mstdn.socialE This user is from outside of this forum
    elfin@mstdn.socialE This user is from outside of this forum
    elfin@mstdn.social
    wrote last edited by
    #18

    @briankrebs Ok ... my bad. I'm going back out for 1.5 Liters of tequila and some cyanide (for myself).

    You gotta be KIDDING me!

    1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

      Link Preview Image
      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

      favicon

      (krebsonsecurity.com)

      briankrebs@infosec.exchangeB This user is from outside of this forum
      briankrebs@infosec.exchangeB This user is from outside of this forum
      briankrebs@infosec.exchange
      wrote last edited by
      #19

      It's possible this set of instructions by the CISA contractor might have caused all the trouble:

      viss@mastodon.socialV demiurg@fosstodon.orgD richlv@mastodon.socialR thetomas@social.toot9.deT ncrazed@fd00.spaceN 5 Replies Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

        Link Preview Image
        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

        favicon

        (krebsonsecurity.com)

        lahosken@hachyderm.ioL This user is from outside of this forum
        lahosken@hachyderm.ioL This user is from outside of this forum
        lahosken@hachyderm.io
        wrote last edited by
        #20

        @briankrebs The White House got mad at that other Krebs guy for "censorship" at CISA. https://www.whitehouse.gov/presidential-actions/2025/04/addressing-risks-from-chris-krebs-and-government-censorship/ I guess he was censoring the keys then?

        1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

          Link Preview Image
          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

          favicon

          (krebsonsecurity.com)

          kevinashworth@mastodon.socialK This user is from outside of this forum
          kevinashworth@mastodon.socialK This user is from outside of this forum
          kevinashworth@mastodon.social
          wrote last edited by
          #21

          @briankrebs
          How Musk-esque of him.

          1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            It's possible this set of instructions by the CISA contractor might have caused all the trouble:

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote last edited by
            #22

            @briankrebs dying to know how that person was selected

            felipe@social.treehouse.systemsF viss@mastodon.socialV 2 Replies Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

              Link Preview Image
              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

              favicon

              (krebsonsecurity.com)

              relasolmi@mastodon.socialR This user is from outside of this forum
              relasolmi@mastodon.socialR This user is from outside of this forum
              relasolmi@mastodon.social
              wrote last edited by
              #23

              @briankrebs 😮

              1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                Link Preview Image
                CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                favicon

                (krebsonsecurity.com)

                somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                somevegancheeseisok@mastodon.social
                wrote last edited by
                #24

                @briankrebs oh jeez

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                  Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                  Link Preview Image
                  CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                  favicon

                  (krebsonsecurity.com)

                  tirrimas@beige.partyT This user is from outside of this forum
                  tirrimas@beige.partyT This user is from outside of this forum
                  tirrimas@beige.party
                  wrote last edited by
                  #25

                  @briankrebs vibe security

                  1 Reply Last reply
                  0
                  • theyosh@mastodon.theyosh.nlT theyosh@mastodon.theyosh.nl

                    @briankrebs We blame an AI agent for this....

                    What a fuck-up!!!

                    risc@wetdry.worldR This user is from outside of this forum
                    risc@wetdry.worldR This user is from outside of this forum
                    risc@wetdry.world
                    wrote last edited by
                    #26

                    @theyosh AI agents don't do this. stupidity does.

                    @briankrebs

                    1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @briankrebs dying to know how that person was selected

                      felipe@social.treehouse.systemsF This user is from outside of this forum
                      felipe@social.treehouse.systemsF This user is from outside of this forum
                      felipe@social.treehouse.systems
                      wrote last edited by
                      #27

                      @Viss @briankrebs they probably get a lot done very quickly

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                        demiurg@fosstodon.orgD This user is from outside of this forum
                        demiurg@fosstodon.orgD This user is from outside of this forum
                        demiurg@fosstodon.org
                        wrote last edited by
                        #28

                        @briankrebs Yes and disabling the warnings and pushing creds in plain text to repos and having it public and having all of them in one repo and then it's for CISA... that is as FUBAR as it can get.

                        1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                          Link Preview Image
                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                          favicon

                          (krebsonsecurity.com)

                          felipeb@hachyderm.ioF This user is from outside of this forum
                          felipeb@hachyderm.ioF This user is from outside of this forum
                          felipeb@hachyderm.io
                          wrote last edited by
                          #29

                          @briankrebs

                          Link Preview Image
                          1 Reply Last reply
                          0
                          • viss@mastodon.socialV viss@mastodon.social

                            @briankrebs dying to know how that person was selected

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote last edited by
                            #30

                            @briankrebs because i actually reached out to cisa in the past, asking how to work for them. they told me the only way to do it was unpaid, and condesendingly told me i should do it 'because i love my country'. many others were getting paid. so, needless to say, theres a little club, and im not in it.

                            but this guy was.
                            so i reeeeeally wanna know

                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                              Link Preview Image
                              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                              favicon

                              (krebsonsecurity.com)

                              justcameheretosay@mastodon.socialJ This user is from outside of this forum
                              justcameheretosay@mastodon.socialJ This user is from outside of this forum
                              justcameheretosay@mastodon.social
                              wrote last edited by
                              #31

                              @briankrebs

                              Nightwing employee? This outfit?

                              Link Preview Image
                              Threat Convergence: Staying Ahead of Coordinated Attacks | Nightwing posted on the topic | LinkedIn

                              #ICYMI 🚨 Threat actors aren't slowing down—and neither should your defenses. The #TeamNightwing intelligence experts have identified a concerning trend: threat convergence. Attackers are no longer using isolated tactics. Instead, they are combining multiple sophisticated techniques in coordinated campaigns. Full breakdown of what you need to know ⤵️ https://lnkd.in/einXizGm

                              favicon

                              LinkedIn (www.linkedin.com)

                              justcameheretosay@mastodon.socialJ 1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                                richlv@mastodon.socialR This user is from outside of this forum
                                richlv@mastodon.socialR This user is from outside of this forum
                                richlv@mastodon.social
                                wrote last edited by
                                #32

                                @briankrebs Where are these from? Didn’t see in the article.

                                briankrebs@infosec.exchangeB 1 Reply Last reply
                                0
                                • richlv@mastodon.socialR richlv@mastodon.social

                                  @briankrebs Where are these from? Didn’t see in the article.

                                  briankrebs@infosec.exchangeB This user is from outside of this forum
                                  briankrebs@infosec.exchangeB This user is from outside of this forum
                                  briankrebs@infosec.exchange
                                  wrote last edited by
                                  #33

                                  @richlv from dude's exposed GitHub repo.

                                  1 Reply Last reply
                                  1
                                  0
                                  • R relay@relay.infosec.exchange shared this topic
                                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                    Link Preview Image
                                    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                    favicon

                                    (krebsonsecurity.com)

                                    krypt3ia@infosec.exchangeK This user is from outside of this forum
                                    krypt3ia@infosec.exchangeK This user is from outside of this forum
                                    krypt3ia@infosec.exchange
                                    wrote last edited by
                                    #34

                                    @briankrebs Our tax dollars at work

                                    viss@mastodon.socialV 1 Reply Last reply
                                    0
                                    • krypt3ia@infosec.exchangeK krypt3ia@infosec.exchange

                                      @briankrebs Our tax dollars at work

                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.social
                                      wrote last edited by
                                      #35

                                      @krypt3ia @briankrebs which is ironic, because ive talked to almost half a dozen shops who cisa was paying as their outsourced assessment teams, but when i asked to be one of those they told me to fuck off, then 'how dare you'd me because i asked to be paid for my work. i have all the receipts. made sure to keep those emails tagged.

                                      krypt3ia@infosec.exchangeK 1 Reply Last reply
                                      0
                                      • viss@mastodon.socialV viss@mastodon.social

                                        @krypt3ia @briankrebs which is ironic, because ive talked to almost half a dozen shops who cisa was paying as their outsourced assessment teams, but when i asked to be one of those they told me to fuck off, then 'how dare you'd me because i asked to be paid for my work. i have all the receipts. made sure to keep those emails tagged.

                                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                                        krypt3ia@infosec.exchange
                                        wrote last edited by
                                        #36

                                        @Viss @briankrebs No bid contract

                                        1 Reply Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                          Link Preview Image
                                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                          favicon

                                          (krebsonsecurity.com)

                                          bbdd333@infosec.exchangeB This user is from outside of this forum
                                          bbdd333@infosec.exchangeB This user is from outside of this forum
                                          bbdd333@infosec.exchange
                                          wrote last edited by
                                          #37

                                          @briankrebs “Currently, there is no indication that any sEnSiTIVe datA was compromised as a result of this incident,” the CISA spokesperson wrote. "I mean, of course, sensitive data was exposed, but not sEnSiTIVe datA."

                                          viss@mastodon.socialV 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups