Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Scheduled Pinned Locked Moved Uncategorized
55 Posts 43 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote last edited by
    #1

    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    Link Preview Image
    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

    favicon

    (krebsonsecurity.com)

    jab01701mid@mastodon.socialJ legit_spaghetti@mastodo.neoliber.alL theyosh@mastodon.theyosh.nlT pq1r@tech.lgbtP generalx@freeradical.zoneG 32 Replies Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

      Link Preview Image
      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

      favicon

      (krebsonsecurity.com)

      jab01701mid@mastodon.socialJ This user is from outside of this forum
      jab01701mid@mastodon.socialJ This user is from outside of this forum
      jab01701mid@mastodon.social
      wrote last edited by
      #2

      @briankrebs Are you seriously telling me that somebody stored AWS govcloud secrets in a github repo ? In a file called "Important AWS Tokens" ? Do they not know who github is ? Is it intentional ?

      Has that person been fired into the sun yet, along with whoever hired them ?

      guillotine_jones@beige.partyG dogriley@opensocial.mediaD G 3 Replies Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

        Link Preview Image
        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

        favicon

        (krebsonsecurity.com)

        legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
        legit_spaghetti@mastodo.neoliber.alL This user is from outside of this forum
        legit_spaghetti@mastodo.neoliber.al
        wrote last edited by
        #3

        @briankrebs

        one of the most egregious government data leaks in recent history

        The word "recent" is doing a lot of heavy lifting here. Like, this is a colossal fuckup, but we've had a lot of other colossal fuckups recently, so... y'know, context.

        christopherkunz@chaos.socialC 1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

          Link Preview Image
          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

          favicon

          (krebsonsecurity.com)

          theyosh@mastodon.theyosh.nlT This user is from outside of this forum
          theyosh@mastodon.theyosh.nlT This user is from outside of this forum
          theyosh@mastodon.theyosh.nl
          wrote last edited by
          #4

          @briankrebs We blame an AI agent for this....

          What a fuck-up!!!

          risc@wetdry.worldR 1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

            Link Preview Image
            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

            favicon

            (krebsonsecurity.com)

            pq1r@tech.lgbtP This user is from outside of this forum
            pq1r@tech.lgbtP This user is from outside of this forum
            pq1r@tech.lgbt
            wrote last edited by
            #5

            @briankrebs He surely covered the A in the CIA triad very well. The availability of the keys is global.

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

              Link Preview Image
              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

              favicon

              (krebsonsecurity.com)

              generalx@freeradical.zoneG This user is from outside of this forum
              generalx@freeradical.zoneG This user is from outside of this forum
              generalx@freeradical.zone
              wrote last edited by
              #6

              @briankrebs

              The 'S' in CISA stands for secrets.

              #gitguardian

              1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                Link Preview Image
                CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                favicon

                (krebsonsecurity.com)

                quatermasstools@infosec.exchangeQ This user is from outside of this forum
                quatermasstools@infosec.exchangeQ This user is from outside of this forum
                quatermasstools@infosec.exchange
                wrote last edited by
                #7

                @briankrebs ooops-sec

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                  Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                  Link Preview Image
                  CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                  favicon

                  (krebsonsecurity.com)

                  chux0r@infosec.exchangeC This user is from outside of this forum
                  chux0r@infosec.exchangeC This user is from outside of this forum
                  chux0r@infosec.exchange
                  wrote last edited by
                  #8

                  @briankrebs That sounds pretty bad, sure- but remember, whomever is left over there has the most important thing, which is loyalty.

                  lawyersgunsnmoney@mstdn.socialL 1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                    Link Preview Image
                    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                    favicon

                    (krebsonsecurity.com)

                    jonhendry@iosdev.spaceJ This user is from outside of this forum
                    jonhendry@iosdev.spaceJ This user is from outside of this forum
                    jonhendry@iosdev.space
                    wrote last edited by
                    #9

                    @briankrebs

                    Lol. "You idiot you're supposed to improve security not facilitate security failures!"

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                      Link Preview Image
                      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                      favicon

                      (krebsonsecurity.com)

                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.social
                      wrote last edited by
                      #10

                      @briankrebs oh. k8s. that tells me everything i need to know

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                        Link Preview Image
                        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                        favicon

                        (krebsonsecurity.com)

                        hufnagel@mastodon.deH This user is from outside of this forum
                        hufnagel@mastodon.deH This user is from outside of this forum
                        hufnagel@mastodon.de
                        wrote last edited by
                        #11

                        @briankrebs
                        Seems they don't have anything to hide 🫣

                        guillotine_jones@beige.partyG 1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                          Link Preview Image
                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                          favicon

                          (krebsonsecurity.com)

                          cykonot@mas.toC This user is from outside of this forum
                          cykonot@mas.toC This user is from outside of this forum
                          cykonot@mas.to
                          wrote last edited by
                          #12

                          @briankrebs government contractors representing massive security threats? Say it ain't so... Why didn't this pop up on my palantir dashboard???

                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                            Link Preview Image
                            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                            favicon

                            (krebsonsecurity.com)

                            danielkennedy74@infosec.exchangeD This user is from outside of this forum
                            danielkennedy74@infosec.exchangeD This user is from outside of this forum
                            danielkennedy74@infosec.exchange
                            wrote last edited by
                            #13

                            @briankrebs I shouldn't be laughing.

                            Workspace is misspelled.

                            Important tokens, as opposed to the unimportant ones.

                            1 Reply Last reply
                            0
                            • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                              @briankrebs Are you seriously telling me that somebody stored AWS govcloud secrets in a github repo ? In a file called "Important AWS Tokens" ? Do they not know who github is ? Is it intentional ?

                              Has that person been fired into the sun yet, along with whoever hired them ?

                              guillotine_jones@beige.partyG This user is from outside of this forum
                              guillotine_jones@beige.partyG This user is from outside of this forum
                              guillotine_jones@beige.party
                              wrote last edited by
                              #14

                              @jab01701mid @briankrebs
                              Was the miscreant who stored high-security US government info on a github repo a Musk DOGE bro, by any chance?
                              Asking for the schadenfreude.

                              jab01701mid@mastodon.socialJ 1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                Link Preview Image
                                CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                favicon

                                (krebsonsecurity.com)

                                elfin@mstdn.socialE This user is from outside of this forum
                                elfin@mstdn.socialE This user is from outside of this forum
                                elfin@mstdn.social
                                wrote last edited by
                                #15

                                @briankrebs I'm out of popcorn ... but there's a theater a few blocks away! Back in a sec to read this.

                                elfin@mstdn.socialE 1 Reply Last reply
                                0
                                • hufnagel@mastodon.deH hufnagel@mastodon.de

                                  @briankrebs
                                  Seems they don't have anything to hide 🫣

                                  guillotine_jones@beige.partyG This user is from outside of this forum
                                  guillotine_jones@beige.partyG This user is from outside of this forum
                                  guillotine_jones@beige.party
                                  wrote last edited by
                                  #16

                                  @Hufnagel @briankrebs
                                  ...They don't have anything to hide anymore.

                                  1 Reply Last reply
                                  0
                                  • guillotine_jones@beige.partyG guillotine_jones@beige.party

                                    @jab01701mid @briankrebs
                                    Was the miscreant who stored high-security US government info on a github repo a Musk DOGE bro, by any chance?
                                    Asking for the schadenfreude.

                                    jab01701mid@mastodon.socialJ This user is from outside of this forum
                                    jab01701mid@mastodon.socialJ This user is from outside of this forum
                                    jab01701mid@mastodon.social
                                    wrote last edited by
                                    #17

                                    @Guillotine_Jones @briankrebs Q: How can I exfilltrate secrets without being seen to be exfilltrating secrets ?
                                    A: github

                                    1 Reply Last reply
                                    0
                                    • elfin@mstdn.socialE elfin@mstdn.social

                                      @briankrebs I'm out of popcorn ... but there's a theater a few blocks away! Back in a sec to read this.

                                      elfin@mstdn.socialE This user is from outside of this forum
                                      elfin@mstdn.socialE This user is from outside of this forum
                                      elfin@mstdn.social
                                      wrote last edited by
                                      #18

                                      @briankrebs Ok ... my bad. I'm going back out for 1.5 Liters of tequila and some cyanide (for myself).

                                      You gotta be KIDDING me!

                                      1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                        Link Preview Image
                                        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                        favicon

                                        (krebsonsecurity.com)

                                        briankrebs@infosec.exchangeB This user is from outside of this forum
                                        briankrebs@infosec.exchangeB This user is from outside of this forum
                                        briankrebs@infosec.exchange
                                        wrote last edited by
                                        #19

                                        It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                                        viss@mastodon.socialV demiurg@fosstodon.orgD richlv@mastodon.socialR thetomas@social.toot9.deT ncrazed@fd00.spaceN 5 Replies Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                          Link Preview Image
                                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                          favicon

                                          (krebsonsecurity.com)

                                          lahosken@hachyderm.ioL This user is from outside of this forum
                                          lahosken@hachyderm.ioL This user is from outside of this forum
                                          lahosken@hachyderm.io
                                          wrote last edited by
                                          #20

                                          @briankrebs The White House got mad at that other Krebs guy for "censorship" at CISA. https://www.whitehouse.gov/presidential-actions/2025/04/addressing-risks-from-chris-krebs-and-government-censorship/ I guess he was censoring the keys then?

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups