Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Scheduled Pinned Locked Moved Uncategorized
55 Posts 43 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    Link Preview Image
    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

    favicon

    (krebsonsecurity.com)

    B This user is from outside of this forum
    B This user is from outside of this forum
    boombastic@social.outhill.cc
    wrote last edited by
    #41

    @briankrebs this is unbelievable

    1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

      Link Preview Image
      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

      favicon

      (krebsonsecurity.com)

      xyhhx@438punk.houseX This user is from outside of this forum
      xyhhx@438punk.houseX This user is from outside of this forum
      xyhhx@438punk.house
      wrote last edited by
      #42

      @briankrebs bruh what the fuck lmao

      1 Reply Last reply
      0
      • justcameheretosay@mastodon.socialJ justcameheretosay@mastodon.social

        @briankrebs

        Nightwing employee? This outfit?

        Link Preview Image
        Threat Convergence: Staying Ahead of Coordinated Attacks | Nightwing posted on the topic | LinkedIn

        #ICYMI 🚨 Threat actors aren't slowing down—and neither should your defenses. The #TeamNightwing intelligence experts have identified a concerning trend: threat convergence. Attackers are no longer using isolated tactics. Instead, they are combining multiple sophisticated techniques in coordinated campaigns. Full breakdown of what you need to know ⤵️ https://lnkd.in/einXizGm

        favicon

        LinkedIn (www.linkedin.com)

        justcameheretosay@mastodon.socialJ This user is from outside of this forum
        justcameheretosay@mastodon.socialJ This user is from outside of this forum
        justcameheretosay@mastodon.social
        wrote last edited by
        #43

        @briankrebs

        One more Nightwing LinkedIn post, from three days ago.

        Link Preview Image
        #definingtheedge | Nightwing

        Cyber threats in the space domain aren’t theoretical, they’re persistent, asymmetric, and accelerating. From ground infrastructure to on-orbit systems, Nightwing helps uncover critical vulnerabilities before adversaries can exploit them, strengthening the resilience of the architectures our national security depends on. That’s why we’re proud to have sponsored Tectonic and Payload's Inside the Dome this week. Bringing together leaders across government and industry it’s clear that cyber resiliency isn’t optional – it’s foundational to every space mission. United States Space Force // United States Department of War #DefiningTheEdge

        favicon

        LinkedIn (www.linkedin.com)

        1 Reply Last reply
        0
        • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

          @briankrebs Are you seriously telling me that somebody stored AWS govcloud secrets in a github repo ? In a file called "Important AWS Tokens" ? Do they not know who github is ? Is it intentional ?

          Has that person been fired into the sun yet, along with whoever hired them ?

          G This user is from outside of this forum
          G This user is from outside of this forum
          gerardthornley@hachyderm.io
          wrote last edited by
          #44

          @jab01701mid @briankrebs isn't the real wtf storing secrets in a git repo, let alone pushing it to github?

          jab01701mid@mastodon.socialJ 1 Reply Last reply
          0
          • G gerardthornley@hachyderm.io

            @jab01701mid @briankrebs isn't the real wtf storing secrets in a git repo, let alone pushing it to github?

            jab01701mid@mastodon.socialJ This user is from outside of this forum
            jab01701mid@mastodon.socialJ This user is from outside of this forum
            jab01701mid@mastodon.social
            wrote last edited by
            #45

            @GerardThornley @briankrebs I guess you have to store secrets somewhere, in your source or CI/CD pipeline playbook. I hope people are not checking in private keys, or the CEO's email password.

            But govcloud IIRC is basically AWS but "secure for fedramp". Then using "github" for your source control is like the Manhattan Project keeping their notebooks in the local college library, but in a locked room.

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

              Link Preview Image
              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

              favicon

              (krebsonsecurity.com)

              snakeoilsalesman@mastodon.socialS This user is from outside of this forum
              snakeoilsalesman@mastodon.socialS This user is from outside of this forum
              snakeoilsalesman@mastodon.social
              wrote last edited by
              #46

              @briankrebs csv password docs... wow, just wow.

              1 Reply Last reply
              0
              • chux0r@infosec.exchangeC chux0r@infosec.exchange

                @briankrebs That sounds pretty bad, sure- but remember, whomever is left over there has the most important thing, which is loyalty.

                lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
                lawyersgunsnmoney@mstdn.socialL This user is from outside of this forum
                lawyersgunsnmoney@mstdn.social
                wrote last edited by
                #47

                @chux0r @briankrebs This is correct. The regime shitcanned everyone associated Biden’s CISA, including the contractors and brought their own people in. Watched it happen

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                  thetomas@social.toot9.deT This user is from outside of this forum
                  thetomas@social.toot9.deT This user is from outside of this forum
                  thetomas@social.toot9.de
                  wrote last edited by
                  #48

                  @briankrebs Seems this dude doesn't know how git works and the organisation did not enforced Separation of work and private stuff (on different devices!).

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                    Link Preview Image
                    CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                    favicon

                    (krebsonsecurity.com)

                    hennichodernich@radiosocial.deH This user is from outside of this forum
                    hennichodernich@radiosocial.deH This user is from outside of this forum
                    hennichodernich@radiosocial.de
                    wrote last edited by
                    #49

                    @briankrebs Worskpace

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                      Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                      Link Preview Image
                      CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                      favicon

                      (krebsonsecurity.com)

                      ppxl@social.tchncs.deP This user is from outside of this forum
                      ppxl@social.tchncs.deP This user is from outside of this forum
                      ppxl@social.tchncs.de
                      wrote last edited by
                      #50

                      @briankrebs can't make this shit up 😳 anyway I am off for some gardening, enough of those pesky computers

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                        Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                        Link Preview Image
                        CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                        favicon

                        (krebsonsecurity.com)

                        grumpydad@infosec.exchangeG This user is from outside of this forum
                        grumpydad@infosec.exchangeG This user is from outside of this forum
                        grumpydad@infosec.exchange
                        wrote last edited by
                        #51

                        @briankrebs There's no way this is not intentional.

                        1 Reply Last reply
                        0
                        • legit_spaghetti@mastodo.neoliber.alL legit_spaghetti@mastodo.neoliber.al

                          @briankrebs

                          one of the most egregious government data leaks in recent history

                          The word "recent" is doing a lot of heavy lifting here. Like, this is a colossal fuckup, but we've had a lot of other colossal fuckups recently, so... y'know, context.

                          christopherkunz@chaos.socialC This user is from outside of this forum
                          christopherkunz@chaos.socialC This user is from outside of this forum
                          christopherkunz@chaos.social
                          wrote last edited by
                          #52

                          @Legit_Spaghetti @briankrebs "recent history" as in "this week".

                          And it's only Tuesday, so...

                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                            Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                            Link Preview Image
                            CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                            favicon

                            (krebsonsecurity.com)

                            okuna@social.tchncs.deO This user is from outside of this forum
                            okuna@social.tchncs.deO This user is from outside of this forum
                            okuna@social.tchncs.de
                            wrote last edited by
                            #53

                            @briankrebs make something idiot proof and nature will create a better idiot

                            Scnr

                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

                              Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

                              Link Preview Image
                              CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

                              favicon

                              (krebsonsecurity.com)

                              airwhale@beige.partyA This user is from outside of this forum
                              airwhale@beige.partyA This user is from outside of this forum
                              airwhale@beige.party
                              wrote last edited by
                              #54

                              @briankrebs

                              So, does any of keys unlock the repo where the unredacted Epstein files are stored?

                              1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                It's possible this set of instructions by the CISA contractor might have caused all the trouble:

                                ncrazed@fd00.spaceN This user is from outside of this forum
                                ncrazed@fd00.spaceN This user is from outside of this forum
                                ncrazed@fd00.space
                                wrote last edited by
                                #55

                                @briankrebs are these LLM instructions or a note to self kind of deal? 😬

                                1 Reply Last reply
                                0
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups