Congressional lawmakers are demanding answers from CISA after a contractor exposed sensitive agency credentials and internal secrets on a public GitHub repository, prompting urgent security remediation efforts.
Key Points
- A CISA contractor created a public GitHub profile named "Private-CISA" that contained plaintext credentials for numerous internal agency systems.
- The repository, active since November 2025, included an RSA private key that granted broad access to CISA’s enterprise GitHub organization and CI/CD pipelines.
- Sen. Maggie Hassan and Rep. Bennie Thompson have launched formal inquiries into the agency's internal security culture and contractor management practices.
- Security researchers at Truffle Security identified that the repository was used to synchronize work files, with sensitive data additions occurring as recently as April 2026.
- CISA is currently working to invalidate and rotate the exposed credentials, though some security experts warn that other leaked keys may remain active.