In stunning display of stupid, secret CISA credentials found in public GitHub repo
Source
Published
TL;DR
AI GeneratedA security researcher discovered that America’s Cybersecurity & Infrastructure Agency (CISA) had exposed plaintext passwords, SSH private keys, and other sensitive assets in a public GitHub repo named “Private-CISA” since November 2025. The repo's administrator had disabled GitHub’s default protections against committing secrets, allowing unauthorized access. Testing confirmed the seriousness of the breach, with credentials from the repo granting high-level access to Amazon Web Services GovCloud accounts. The repo was linked to CISA contractor Nightwing, which has not publicly commented on the issue. This incident adds to a series of mishaps by CISA, including a previous incident involving sensitive government documents uploaded to ChatGPT.