{"id":12973,"date":"2026-05-19T10:04:51","date_gmt":"2026-05-19T10:04:51","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/19\/cisa-admin-exposes-aws-govcloud-credentials-on-public-github-repository\/"},"modified":"2026-05-19T10:04:51","modified_gmt":"2026-05-19T10:04:51","slug":"cisa-admin-exposes-aws-govcloud-credentials-on-public-github-repository","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/19\/cisa-admin-exposes-aws-govcloud-credentials-on-public-github-repository\/","title":{"rendered":"CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository"},"content":{"rendered":"<p>    CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A major security lapse has exposed highly sensitive <a href=\"https:\/\/cybersecuritynews.com\/russian-hackers-stole-data-from-u-s-government-networks\/\" target=\"_blank\" rel=\"noreferrer noopener\">U.S. government cloud credentials <\/a>after a contractor working with the Cybersecurity and Infrastructure Security Agency (CISA) accidentally published them in a public GitHub repository.<\/p>\n<p>The repository, named \u201cPrivate-CISA,\u201d remained publicly accessible until mid-May 2026 and contained a wide range of sensitive data, including AWS GovCloud credentials, plaintext passwords,<a href=\"https:\/\/cybersecuritynews.com\/chrome-extensions-vulnerability-exposes-api-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\"> API tokens<\/a>, and internal system details.<\/p>\n<p>Security researchers warn that this incident could rank among the most serious government-related data exposures in recent years.<\/p>\n<p>Guillaume Valadon, a researcher at GitGuardian, first identified the issue. This firm continuously scans public repositories for exposed secrets.<\/p>\n<p>According to Valadon, the repository contained \u201cextremely sensitive\u201d information, and attempts to alert the owner went unanswered at first.<\/p>\n<p>The findings were later shared with KrebsOnSecurity, prompting further investigation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-govcloud-credentials-exposed\"><strong>GovCloud Credentials Exposed<\/strong><\/h2>\n<p>Analysis revealed that the repository included administrative credentials for at least three AWS GovCloud environments, specifically designed to handle sensitive U.S. government workloads.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEheCESxr3O4t6dk0Jom1HRY8Wv6vP1HuRBEVrZrEDsmHfJ1P6SpzCTt1QZyUf2_Zp7nLgCovBlhnhFChxaSMshjB3OMgYoihDbyhhykfem5tMW9pPdbMf1vG8OPwel9FghvCDCEfKKmAAPgCcaGJ1hYJ5WBQN2lJmz9p3alEiNuHJByvO5aG6KddYg4gtg\/s1600\/Screenshot%25202026-05-19%2520105718%2520%25281%2529.webp?ssl=1\" alt=\"screenshot of the deleted \u201cPrivate CISA\u201d GitHub repository( source :krebsonsecurity)\"><figcaption class=\"wp-element-caption\">screenshot of the deleted \u201cPrivate CISA\u201d GitHub repository( source :krebsonsecurity)<\/figcaption><\/figure>\n<p>In addition, a file named \u201cAWS-Workspace-Firefox-Passwords.csv\u201d <a href=\"https:\/\/cybersecuritynews.com\/900-websites-10m-passwords-plaintext-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">exposed dozens of plaintext usernames and passwords<\/a> tied to internal CISA systems, including a DevSecOps environment referred to as \u201cLZ-DSO.\u201d<\/p>\n<p>Philippe Caturegli, founder of security consultancy Seralys, confirmed that some of the exposed <a href=\"https:\/\/cybersecuritynews.com\/1800-android-and-ios-apps\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS credentials<\/a> were still valid at the time of discovery and provided high-level access.<\/p>\n<p>He noted that the repository also contained credentials for CISA\u2019s internal \u201cartifactory,\u201d a centralized system for storing and distributing software components.<\/p>\n<p>This type of access could allow attackers to insert malicious code into software pipelines.<\/p>\n<p>For example, if a threat actor compromised the artifactory, they could embed backdoors into legitimate software updates, potentially affecting multiple systems during deployment.<\/p>\n<p>Researchers also highlighted poor security practices within the repository. Sensitive data was stored in plain text, and <a href=\"https:\/\/cybersecuritynews.com\/packagist-urges-immediate-composer-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub\u2019s<\/a> built-in secret scanning protections had been deliberately turned off.<\/p>\n<p>Commit logs suggest the repository may have been used as a personal workspace or a file synchronization tool rather than as a secure development project.<\/p>\n<p>\u201cThe patterns indicate this was likely used to sync files between different machines, possibly a work and home environment,\u201d Caturegli explained. \u201cBut that doesn\u2019t reduce the severity it actually makes it worse.\u201d<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi-GKvdlLtBiBWFEiukC5CTfGRmVsb_bbzMmNAsP391I1SBepOje44uHbkYYtOqjekuhFTLnWbG_DL67TpjqEVXgSPaOxU3lnB6y6Fi6CTVX2w-3qsOMTkb7nrT0x6cxRdTo8ch4YSZjdvKYsL9zhNssRuQMfcj_BdvImj2MtplJhmVxObiIxEFmzpiKRM\/s1600\/Screenshot%25202026-05-19%2520105729%2520%25281%2529.webp?ssl=1\" alt=\"Private CISA exposed plaintext GovCloud credentials(source :krebsonsecurity)\"><figcaption class=\"wp-element-caption\">Private CISA exposed plaintext GovCloud credentials(source :krebsonsecurity)<\/figcaption><\/figure>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2026\/05\/cisa-admin-leaked-aws-govcloud-keys-on-github\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">KrebsOnSecurity reported that<\/a> the exposed repository was linked to a contractor from Nightwing, a U.S.-based government services firm.<\/p>\n<p>The account had been active since 2018, while the \u201cPrivate-CISA\u201d repository was created in November 2025.<\/p>\n<p>Despite the repository being taken offline shortly after disclosure, the exposed AWS credentials reportedly remained valid for nearly 48 hours afterward, increasing the potential risk window.<\/p>\n<p>CISA acknowledged the incident and stated that it is actively investigating. The agency noted there is currently no evidence of active exploitation but emphasized that additional safeguards are being implemented.<\/p>\n<p>The exposure comes at a challenging time for CISA, which has reportedly lost a significant portion of its workforce due to budget cuts and restructuring.<\/p>\n<p>Security experts warn that such operational pressures can increase the likelihood of misconfigurations and human error.<\/p>\n<p>Overall, the incident underscores a critical lesson in cybersecurity: even highly sensitive environments can be compromised by basic mistakes such as poor credential management and unsafe development practices.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-admin-exposes-aws-govcloud-credentials\/\">CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-admin-exposes-aws-govcloud-credentials\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository A major security lapse has exposed highly sensitive U.S. government cloud credentials after a contractor working with the Cybersecurity and Infrastructure Security Agency (CISA) accidentally published them in a public GitHub repository. The repository, named \u201cPrivate-CISA,\u201d remained publicly accessible until mid-May 2026 and contained a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2478,129,63,156],"tags":[130],"class_list":["post-12973","post","type-post","status-publish","format-standard","hentry","category-aws","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12973"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12973"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12973\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12973"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12973"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}