Who guards the #infosec guards? #CISA embarrassed this week as attackers found a public #GitHub repository called "Private-CISA" w/ 844MB of plain-text passwords, AWS tokens & Entra @CISAgov ID SAML certs exposed since 11/25. HT @guedou of @gitguardian. https://cybersec.gitguardian.com/s/how-we-got-a-cisa-github-leak-taken-down-in-under-a-day-27502
benrothke@infosec.exchange
@benrothke@infosec.exchange
Posts
-
Who guards the #infosec guards? -
Looks to be an interesting & important @ZeroNetworks webinar June 11: Mythos & Daybreak: What Boards Are Asking & What to Actually Do About It.Looks to be an interesting & important @ZeroNetworks webinar June 11: Mythos & Daybreak: What Boards Are Asking & What to Actually Do About It. #Claude #Mythos & #OpenAI #Daybreak have changed the math on vulnerability, discovery & exploitation overnight. https://api.cyfluencer.com/s/live-session-mythos-and-daybreak-what-boards-are-asking-and-what-to-actually-do-about-it-27407
-
How to Secure YourHow to Secure Your .MD files & Close A Critical Data Security Gap in the Age of Vibe Coding The .md file, long the domain of README documentation and technical wikis, has quietly become one of the most sensitive file types in the modern enterprise. The security industry has not caught up.