Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Scheduled Pinned Locked Moved Uncategorized
55 Posts 43 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • viss@mastodon.socialV viss@mastodon.social

    @briankrebs dying to know how that person was selected

    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.social
    wrote last edited by
    #30

    @briankrebs because i actually reached out to cisa in the past, asking how to work for them. they told me the only way to do it was unpaid, and condesendingly told me i should do it 'because i love my country'. many others were getting paid. so, needless to say, theres a little club, and im not in it.

    but this guy was.
    so i reeeeeally wanna know

    1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

      Link Preview Image
      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

      favicon

      (krebsonsecurity.com)

      justcameheretosay@mastodon.socialJ This user is from outside of this forum
      justcameheretosay@mastodon.socialJ This user is from outside of this forum
      justcameheretosay@mastodon.social
      wrote last edited by
      #31

      @briankrebs

      Nightwing employee? This outfit?

      Link Preview Image
      Threat Convergence: Staying Ahead of Coordinated Attacks | Nightwing posted on the topic | LinkedIn

      #ICYMI 🚨 Threat actors aren't slowing down—and neither should your defenses. The #TeamNightwing intelligence experts have identified a concerning trend: threat convergence. Attackers are no longer using isolated tactics. Instead, they are combining multiple sophisticated techniques in coordinated campaigns. Full breakdown of what you need to know ⤵️ https://lnkd.in/einXizGm

      favicon

      LinkedIn (www.linkedin.com)

      justcameheretosay@mastodon.socialJ 1 Reply Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        It's possible this set of instructions by the CISA contractor might have caused all the trouble:

        richlv@mastodon.socialR This user is from outside of this forum
        richlv@mastodon.socialR This user is from outside of this forum
        richlv@mastodon.social
        wrote last edited by
        #32

        @briankrebs Where are these from? Didn’t see in the article.

        briankrebs@infosec.exchangeB 1 Reply Last reply
        0
        • richlv@mastodon.socialR richlv@mastodon.social

          @briankrebs Where are these from? Didn’t see in the article.

          briankrebs@infosec.exchangeB This user is from outside of this forum
          briankrebs@infosec.exchangeB This user is from outside of this forum
          briankrebs@infosec.exchange
          wrote last edited by
          #33

          @richlv from dude's exposed GitHub repo.

          1 Reply Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

            Link Preview Image
            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

            favicon

            (krebsonsecurity.com)

            krypt3ia@infosec.exchangeK This user is from outside of this forum
            krypt3ia@infosec.exchangeK This user is from outside of this forum
            krypt3ia@infosec.exchange
            wrote last edited by
            #34

            @briankrebs Our tax dollars at work

            viss@mastodon.socialV 1 Reply Last reply
            0
            • krypt3ia@infosec.exchangeK krypt3ia@infosec.exchange

              @briankrebs Our tax dollars at work

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote last edited by
              #35

              @krypt3ia @briankrebs which is ironic, because ive talked to almost half a dozen shops who cisa was paying as their outsourced assessment teams, but when i asked to be one of those they told me to fuck off, then 'how dare you'd me because i asked to be paid for my work. i have all the receipts. made sure to keep those emails tagged.

              krypt3ia@infosec.exchangeK 1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                @krypt3ia @briankrebs which is ironic, because ive talked to almost half a dozen shops who cisa was paying as their outsourced assessment teams, but when i asked to be one of those they told me to fuck off, then 'how dare you'd me because i asked to be paid for my work. i have all the receipts. made sure to keep those emails tagged.

                krypt3ia@infosec.exchangeK This user is from outside of this forum
                krypt3ia@infosec.exchangeK This user is from outside of this forum
                krypt3ia@infosec.exchange
                wrote last edited by
                #36

                @Viss @briankrebs No bid contract

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                  Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                  Link Preview Image
                  CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                  favicon

                  (krebsonsecurity.com)

                  bbdd333@infosec.exchangeB This user is from outside of this forum
                  bbdd333@infosec.exchangeB This user is from outside of this forum
                  bbdd333@infosec.exchange
                  wrote last edited by
                  #37

                  @briankrebs “Currently, there is no indication that any sEnSiTIVe datA was compromised as a result of this incident,” the CISA spokesperson wrote. "I mean, of course, sensitive data was exposed, but not sEnSiTIVe datA."

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • bbdd333@infosec.exchangeB bbdd333@infosec.exchange

                    @briankrebs “Currently, there is no indication that any sEnSiTIVe datA was compromised as a result of this incident,” the CISA spokesperson wrote. "I mean, of course, sensitive data was exposed, but not sEnSiTIVe datA."

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote last edited by
                    #38

                    @bbdd333 @briankrebs no logs no crime!

                    1 Reply Last reply
                    0
                    • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                      @briankrebs Are you seriously telling me that somebody stored AWS govcloud secrets in a github repo ? In a file called "Important AWS Tokens" ? Do they not know who github is ? Is it intentional ?

                      Has that person been fired into the sun yet, along with whoever hired them ?

                      dogriley@opensocial.mediaD This user is from outside of this forum
                      dogriley@opensocial.mediaD This user is from outside of this forum
                      dogriley@opensocial.media
                      wrote last edited by
                      #39

                      @jab01701mid @briankrebs

                      At some point its intentional. When you have that type of access it should be assumed it is.

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                        Link Preview Image
                        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                        favicon

                        (krebsonsecurity.com)

                        S This user is from outside of this forum
                        S This user is from outside of this forum
                        spacelifeform@infosec.exchange
                        wrote last edited by
                        #40

                        @briankrebs

                        CISA should know better than to use Cloud. AWS in particular. SMH.

                        1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                          Link Preview Image
                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                          favicon

                          (krebsonsecurity.com)

                          B This user is from outside of this forum
                          B This user is from outside of this forum
                          boombastic@social.outhill.cc
                          wrote last edited by
                          #41

                          @briankrebs this is unbelievable

                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                            Link Preview Image
                            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                            favicon

                            (krebsonsecurity.com)

                            xyhhx@438punk.houseX This user is from outside of this forum
                            xyhhx@438punk.houseX This user is from outside of this forum
                            xyhhx@438punk.house
                            wrote last edited by
                            #42

                            @briankrebs bruh what the fuck lmao

                            1 Reply Last reply
                            0
                            • justcameheretosay@mastodon.socialJ justcameheretosay@mastodon.social

                              @briankrebs

                              Nightwing employee? This outfit?

                              Link Preview Image
                              Threat Convergence: Staying Ahead of Coordinated Attacks | Nightwing posted on the topic | LinkedIn

                              #ICYMI 🚨 Threat actors aren't slowing down—and neither should your defenses. The #TeamNightwing intelligence experts have identified a concerning trend: threat convergence. Attackers are no longer using isolated tactics. Instead, they are combining multiple sophisticated techniques in coordinated campaigns. Full breakdown of what you need to know ⤵️ https://lnkd.in/einXizGm

                              favicon

                              LinkedIn (www.linkedin.com)

                              justcameheretosay@mastodon.socialJ This user is from outside of this forum
                              justcameheretosay@mastodon.socialJ This user is from outside of this forum
                              justcameheretosay@mastodon.social
                              wrote last edited by
                              #43

                              @briankrebs

                              One more Nightwing LinkedIn post, from three days ago.

                              Link Preview Image
                              #definingtheedge | Nightwing

                              Cyber threats in the space domain aren’t theoretical, they’re persistent, asymmetric, and accelerating. From ground infrastructure to on-orbit systems, Nightwing helps uncover critical vulnerabilities before adversaries can exploit them, strengthening the resilience of the architectures our national security depends on. That’s why we’re proud to have sponsored Tectonic and Payload's Inside the Dome this week. Bringing together leaders across government and industry it’s clear that cyber resiliency isn’t optional – it’s foundational to every space mission. United States Space Force // United States Department of War #DefiningTheEdge

                              favicon

                              LinkedIn (www.linkedin.com)

                              1 Reply Last reply
                              0
                              • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                                @briankrebs Are you seriously telling me that somebody stored AWS govcloud secrets in a github repo ? In a file called "Important AWS Tokens" ? Do they not know who github is ? Is it intentional ?

                                Has that person been fired into the sun yet, along with whoever hired them ?

                                G This user is from outside of this forum
                                G This user is from outside of this forum
                                gerardthornley@hachyderm.io
                                wrote last edited by
                                #44

                                @jab01701mid @briankrebs isn't the real wtf storing secrets in a git repo, let alone pushing it to github?

                                jab01701mid@mastodon.socialJ 1 Reply Last reply
                                0
                                • G gerardthornley@hachyderm.io

                                  @jab01701mid @briankrebs isn't the real wtf storing secrets in a git repo, let alone pushing it to github?

                                  jab01701mid@mastodon.socialJ This user is from outside of this forum
                                  jab01701mid@mastodon.socialJ This user is from outside of this forum
                                  jab01701mid@mastodon.social
                                  wrote last edited by
                                  #45

                                  @GerardThornley @briankrebs I guess you have to store secrets somewhere, in your source or CI/CD pipeline playbook. I hope people are not checking in private keys, or the CEO's email password.

                                  But govcloud IIRC is basically AWS but "secure for fedramp". Then using "github" for your source control is like the Manhattan Project keeping their notebooks in the local college library, but in a locked room.

                                  1 Reply Last reply
                                  0
                                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                    Link Preview Image
                                    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                    favicon

                                    (krebsonsecurity.com)

                                    snakeoilsalesman@mastodon.socialS This user is from outside of this forum
                                    snakeoilsalesman@mastodon.socialS This user is from outside of this forum
                                    snakeoilsalesman@mastodon.social
                                    wrote last edited by
                                    #46

                                    @briankrebs csv password docs... wow, just wow.

                                    1 Reply Last reply
                                    0
                                    • chux0r@infosec.exchangeC chux0r@infosec.exchange

                                      @briankrebs That sounds pretty bad, sure- but remember, whomever is left over there has the most important thing, which is loyalty.

                                      lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
                                      lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
                                      lawyersgunsnmoney@mstdn.social
                                      wrote last edited by
                                      #47

                                      @chux0r @briankrebs This is correct. The regime shitcanned everyone associated Biden’s CISA, including the contractors and brought their own people in. Watched it happen

                                      1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                                        thetomas@social.toot9.deT This user is from outside of this forum
                                        thetomas@social.toot9.deT This user is from outside of this forum
                                        thetomas@social.toot9.de
                                        wrote last edited by
                                        #48

                                        @briankrebs Seems this dude doesn't know how git works and the organisation did not enforced Separation of work and private stuff (on different devices!).

                                        1 Reply Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                                          Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                                          Link Preview Image
                                          CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                                          favicon

                                          (krebsonsecurity.com)

                                          hennichodernich@radiosocial.deH This user is from outside of this forum
                                          hennichodernich@radiosocial.deH This user is from outside of this forum
                                          hennichodernich@radiosocial.de
                                          wrote last edited by
                                          #49

                                          @briankrebs Worskpace

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups