Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

We Got a CISA GitHub Leak Taken Down in Under a Day

GitGuardian discovered a critical GitHub leak exposing CISA's internal infrastructure, including hardcoded credentials and API keys. Within 26 hours of reporting, the leak was fully removed, highlighting both the prevalence of secret exposure in repositories and the effectiveness of rapid coordinated response between security researchers and government agencies.

Related stories

  • Lawmakers from both chambers of Congress are demanding answers from CISA after a contractor deliberately published AWS GovCloud keys and other sensitive agency data on a public GitHub account. The agency is still working to contain the breach and invalidate the leaked credentials.