A public GitHub repository tied to a contractor supporting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) exposed plaintext passwords, access tokens, cloud keys, logs, spreadsheets, and deployment files that could provide access to CISA and Department of Homeland Security internal and cloud systems. Researchers from GitGuardian and Seralys reported that the repository, named "Private-CISA", contained administrative credentials for three AWS GovCloud accounts as well as numerous credentials for internal CISA systems; some of the exposed secrets were verified as valid.
The repository was reportedly linked to a Nightwing employee and appears to have been used as an informal working scratchpad rather than a controlled code repository, with commit history indicating GitHub secret-scanning protections had been disabled. After alerts to the contractor reportedly went unanswered, the issue was escalated and the GitHub account was taken offline, but exposed AWS keys were said to remain valid for roughly 48 hours after disclosure. CISA said it is investigating and that it had no indication the credentials were abused, though the incident represents a significant security lapse at the federal agency responsible for civilian cybersecurity.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers said that more than a week after GitGuardian notified CISA of the exposed repository, the agency was still revoking and rotating leaked credentials. The remaining remediation reportedly included an RSA private key that could have enabled broad access to CISA's GitHub environment and CI/CD infrastructure.
Lawmakers including Rep. Bennie Thompson, Rep. Delia Ramirez, and Sen. Maggie Hassan requested briefings from acting CISA Director Nick Andersen on the cause, impact, remediation, and oversight failures tied to the exposed GitHub repository. The request marked a congressional oversight response to the incident.
CISA acknowledged the exposure and said it was investigating the incident. The agency stated there was no indication that sensitive data had been compromised as a result of the leak.
Following notification about the exposed repository, the contractor's GitHub account was removed from public access. Despite that action, reports said some exposed AWS GovCloud credentials remained valid for about 48 hours afterward.
After attempts to notify the contractor about the exposed secrets did not receive a response, the researchers escalated the issue to prompt remediation. The exposure was characterized by one researcher as among the worst credential leaks he had seen.
Security researchers from GitGuardian and Seralys found a public repository containing plaintext passwords, access tokens, AWS GovCloud keys, logs, spreadsheets, and deployment information tied to CISA and Department of Homeland Security systems. Some of the exposed credentials were verified as valid, indicating potential access to internal and cloud environments.
GitGuardian researcher Guillaume Valadon found a publicly accessible GitHub repository named 'Private-CISA' containing extensive CISA-related secrets and infrastructure material. He reported the exposure to CISA on May 14 after determining the repository had been publicly accessible for roughly six months.
A GitHub repository later identified as exposing sensitive CISA-related data was reportedly created by a contractor employee and linked to work supporting CISA. The repository was created publicly and became the location where credentials and operational files accumulated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
22 references tracked. Mallory keeps watching after this page renders.
risky.biz
Open sourcetechdirt.com
Open sourcexakep.ru
Open sourcemalware.news
Open sourcedarkreading.com
Open sourcecio.com
Open sourceaxios.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.