AUTO-UPDATED

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency has released a postmortem report detailing how a contractor’s six-month data leak exposed sensitive AWS GovCloud credentials and internal system passwords.

Key Points

  • A public GitHub repository titled "Private CISA" exposed 844 MB of sensitive data, including administrative AWS GovCloud keys and plaintext passwords.
  • The exposed credentials remained accessible for six months despite nine automated alerts from the security firm GitGuardian.
  • CISA required over 48 hours to invalidate the leaked secrets, citing complex system interconnections and a lack of defined internal reporting channels.
  • The agency has since revoked the contractor's access, rotated all compromised secrets, and committed to improving its incident response playbooks.
  • CISA now advocates for continuous public repository scanning and the establishment of clear, accessible reporting channels for external security researchers.

Why it Matters

This incident highlights critical vulnerabilities in how government agencies manage developer secrets and respond to external security disclosures. By publicly documenting its failures, CISA sets a new standard for transparency that encourages other organizations to prioritize continuous monitoring and streamlined communication with the security research community.
Krebs on Security Published by BrianKrebs
Read original