CISA contractor apparently leaked ‘highly sensitive’ AWS government keys on Github



  • A public GitHub repository called “Private-CISA” exposed highly sensitive internal credentials and systems used by the US Cybersecurity and Infrastructure Security Agency.
  • Security researchers confirmed the authenticity of the leak and described it as one of the worst exposures of government data they have ever seen.
  • The repository, maintained by contractor Nightwing, was eventually shut down and CISA promised safeguards to prevent future incidents.

Investigators have revealed details about what they called “one of the most egregious government data breaches in recent history” involving potentially incredibly sensitive US government information.

Security researcher Guillaume Valadon contacted KrebsOnSecurity to help contact a person in charge of a public GitHub repository.

Leave a Comment

Your email address will not be published. Required fields are marked *