CISA disclosed that a contractor exposed privileged AWS GovCloud keys and other sensitive credentials in a public GitHub repository, triggering an internal response after the leak was reported in May. According to the agency’s forensic and post-mortem findings, the exposure was first flagged by a GitGuardian researcher and relayed through journalist Brian Krebs after the contractor allegedly did not respond to the initial warning. CISA said it took the repository and the associated developer environment offline, revoked the individual’s access, and rotated the exposed secrets.
The agency said its review of repository activity and logs found no evidence that the leaked credentials were used outside CISA and that no customer or mission data was exposed. The incident nevertheless exposed gaps in CISA’s own readiness, including the absence of a preexisting incident response playbook for this type of event and unclear reporting channels for outside researchers. In response, CISA said it is strengthening protections for sensitive material, improving secrets management and rotation, monitoring uploads to public repositories through EDR, simplifying vulnerability reporting, and developing formal playbooks for GitHub-related and similar incidents.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
CISA and four allied cyber authorities published guidance for software vendors on building coordinated vulnerability disclosure programs. The guidance emphasized clear reporting channels, security.txt, prompt acknowledgment of researchers, safe-harbor language, and other practices, and was framed as incorporating lessons from CISA’s own credential-leak reporting failure.
Following the incident, CISA introduced stronger protections for sensitive materials, secret rotation and improved secrets management, monitoring of uploads to public repositories through EDR, clearer researcher reporting channels, and new incident playbooks for GitHub-related and other incidents. The agency also acknowledged it had lacked a prepared incident response playbook during the event.
CISA analyzed the repository and logs and concluded that the leaked credentials were not used outside the agency. It said no customer or mission data was exposed in the incident.
After learning of the leak, CISA took the GitHub repository and associated developer environment offline and revoked the responsible individual's access. The agency also revoked and replaced the exposed credentials as part of containment.
On 2026-07-10, CISA disclosed a forensic/post-mortem report detailing its response to the contractor-caused leak of privileged AWS GovCloud keys and other sensitive credentials. The report described the agency's containment actions, findings, and security changes made afterward.
A GitGuardian researcher discovered sensitive keys and credentials for accessing U.S. government systems exposed in a public GitHub repository. After the contractor reportedly did not respond to the initial warning, the finding was escalated to CISA through journalist Brian Krebs.
On 2026-05-15, CISA learned that a contractor had exposed privileged AWS GovCloud keys in a public GitHub repository. The agency began responding to assess and contain the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcecryptika.com
Open sourcekrebsonsecurity.com
Open sourceblog.gitguardian.com
Open sourcecyberscoop.com
Open sourcetechcrunch.com
Open sourceblog.gitguardian.com
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.