By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Global News TodayGlobal News TodayGlobal News Today
  • World
  • Politics
  • Business
  • Technology
  • Science
  • Entertainment
  • Sports
  • Health
Reading: U.S. cybersecurity agency leaks GovCloud keys on GitHub – Techzine Global
Share
Notification Show More
Font ResizerAa
Global News TodayGlobal News Today
Font ResizerAa
  • World
  • Politics
  • Sports
  • Business
  • Science
  • Technology
  • Entertainment
  • Home
    • Home 1
    • Home 2
    • Home 3
    • Home 4
    • Home 5
  • Demos
  • Categories
    • Technology
    • Business
    • Sports
    • Entertainment
    • World
    • Politics
    • Science
    • Health
  • Bookmarks
  • More Foxiz
    • Sitemap
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

U.S. cybersecurity agency leaks GovCloud keys on GitHub – Techzine Global

Editorial Staff
Last updated: May 20, 2026 8:04 am
Editorial Staff
5 days ago
Share
SHARE

Sensitive access credentials for internal systems and cloud environments belonging to the U.S. cybersecurity watchdog Cybersecurity and Infrastructure Security Agency (CISA) have been publicly exposed on GitHub. 
This was reported by Brian Krebs on his site KrebsOnSecurity. According to security researchers, the data included AWS GovCloud keys, plaintext passwords, and internal DevSecOps files.
The data was stored in a public GitHub repository named Private-CISA, which, according to KrebsOnSecurity, was managed by a CISA contractor. Researchers from security firms GitGuardian and Seralys discovered that the repository provided access to various internal environments and software repositories of the U.S. government.
According to researchers, the leaked files contained administrative keys for multiple AWS GovCloud accounts. AWS GovCloud is a secure cloud environment from Amazon Web Services specifically designed for sensitive U.S. government data.
Researchers from security firm Seralys also say they have confirmed that multiple leaked AWS GovCloud accounts were indeed accessible with high privileges. The repository is also said to have contained CSV files with plaintext usernames and passwords for internal CISA systems.
Furthermore, credentials for internal software repositories and build environments were reportedly leaked. Philippe Caturegli of Seralys warns that access to such repositories is attractive to attackers seeking to embed malware or backdoors into software builds. As a result, compromises could spread further within government environments.
According to GitGuardian, the repository administrator had also disabled GitHub functionality that normally prevents secret keys or passwords from being published publicly. Ars Technica reports that the repository was likely publicly accessible as early as November 2025.
Researchers also found passwords that were relatively easy to guess, such as combinations of platform names with the current year. KrebsOnSecurity reports that the repository was likely used as a synchronization point between the contractor’s various devices.
CISA confirmed to KrebsOnSecurity that the incident is under investigation. According to the agency, there are currently no indications that sensitive data was actually misused. However, the agency says it is taking additional measures to prevent a recurrence.
Notably, according to researchers, some of the leaked AWS keys remained valid for approximately 48 hours after CISA was notified of the breach and the GitHub repository was taken offline.
The repository is said to have been managed by an employee of Nightwing, an American contractor that works for government agencies. Nightwing referred KrebsOnSecurity’s questions to CISA.
CISA / data breach / GitHub
"*" indicates required fields
With a CEO who positively likes to call software automation services …
In recent weeks, alarm bells have been ringing repeatedly over critical vulnerabilities in the Linux kernel. …
Akamai is a cloud cybersecurity company that dedicates itself to the provision of what it calls “superior t…
The hacker group TeamPCP uploaded two malicious versions of the popular Python library LiteLLM to PyPI. Using…
Anthropic allows Project Glasswing partners to share findings from the Mythos cybersecurity model with partie…
Enterprise infrastructure has reached a turning point where planned d…
Continuous deployment offers quicker releases and better software, bu…
If anyone was ever forced to pick the tritest phrase in the world, it…
The new SOC in the Netherlands further strengthens mnemonic’s regio…
How do you ensure your company data is both secure and quickly recove…
“A Buyer’s Guide to Enterprise Linux” comprehensively analyzes the mo…
The Data Protection Guide 2025 explores the essential strategies and…
The white paper “DNS Best Practices” by Infoblox presents essential g…
Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.
© 2026 Dolphin Publications B.V.
All rights reserved.

source

Anthropic and Wall Street Giants Join Forces to Create New A.I. Firm – The New York Times
Tawasol 2026 Opening Address Highlights Promising Tech Opportunities, Youth Engagement – Ammon News
Dixon Tech Q4 Results: Date, Dividend News, Earnings Call Details And Share Price History – NDTV Profit
Google announces the Googlebook, a new breed of built-for-Gemini laptops – Mashable
New Oscars rules: No AI actors, human-written scripts only – DW.com
Share This Article
Facebook Email Print
Previous Article Xi and Putin meet to reaffirm China-Russia ties days after Trump’s visit to Beijing – Audacy
Next Article Senator Murray Questions Secretary Duffy on Corporate-Paid Reality TV Road Trip as Americans Pay Sky-High Gas Prices – Senator Patty Murray (.gov)
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • World
  • Politics
  • Business
  • Technology
  • Science
  • Entertainment
  • Sports
  • Health
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
[mc4wp_form]
Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?